CriticalVulnerability
CVE-2026-108263: Astron Agent code-node execution as root through workflow run endpoints
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-108263
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
Summary
Astron Agent, an agentic workflow platform, prior to 1.1.2 defaults its workflow code-node path (/console-api/workflow/code/run and /workflow/v1/run) to LocalExecutor in core/workflow/engine/nodes/code/code_node.py unless CODE_EXEC_TYPE is changed. LocalExecutor exposes full Python builtins to dynamic code without the documented sandbox restrictions. An authenticated low-privilege tenant can run code as root in the core-workflow container and use shared credentials to bypass tenant checks, read or modify other tenants' data, and disrupt shared services.
Mitigation
This issue is fixed in version 1.1.2.
Topics
Related items
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database