Skip to content
CriticalVulnerability

CVE-2026-108263: Astron Agent code-node execution as root through workflow run endpoints

Identifier
CVE-2026-108263
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.

Summary

Astron Agent, an agentic workflow platform, prior to 1.1.2 defaults its workflow code-node path (/console-api/workflow/code/run and /workflow/v1/run) to LocalExecutor in core/workflow/engine/nodes/code/code_node.py unless CODE_EXEC_TYPE is changed. LocalExecutor exposes full Python builtins to dynamic code without the documented sandbox restrictions. An authenticated low-privilege tenant can run code as root in the core-workflow container and use shared credentials to bypass tenant checks, read or modify other tenants' data, and disrupt shared services.

Mitigation

This issue is fixed in version 1.1.2.