Opening SecureFlowFlowise CSV Agent Prompt Injection to Host-Capable Pyodide
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

FlowiseAI / TrendAI Research aidefend-sf0028

Flowise CSV Agent Prompt Injection to Host-Capable Pyodide

  • Autonomous Agents
  • System Compromise & RCE

An unauthenticated prompt sent to an affected CSV Agent chatflow can make the LLM emit obfuscated Python. Flowise 3.1.2 and earlier validate that output with a static regex blocklist, then execute accepted code through Pyodide without isolating it from host operating-system interfaces.

Mapped threat techniques

  • AML.T0051.000 LLM Prompt Injection: Direct
  • AML.T0107 Exploitation for Defense Evasion
  • AML.T0050 Command and Scripting Interpreter

Source