{"id":"CVE-2026-108263","title":"Astron Agent is an agentic workflow platform for building and running AI agents","summary":"Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engin…","severity":"critical","cvss":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-95","CWE-306","CWE-653","CWE-863","CWE-1392"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T21:17:04.527","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108263","references":[{"url":"https://github.com/iflytek/astron-agent/commit/848daba03e5e045435863815be7ab6dfbcefc18f","label":"security-advisories@github.com"},{"url":"https://github.com/iflytek/astron-agent/commit/ebf074a431e96da0ad9e0a56409d3d2da15eae36","label":"security-advisories@github.com"},{"url":"https://github.com/iflytek/astron-agent/pull/1650","label":"security-advisories@github.com"},{"url":"https://github.com/iflytek/astron-agent/pull/1651","label":"security-advisories@github.com"},{"url":"https://github.com/iflytek/astron-agent/releases/tag/v1.1.2","label":"security-advisories@github.com"},{"url":"https://github.com/iflytek/astron-agent/security/advisories/GHSA-mh3w-4q3f-2fg5","label":"security-advisories@github.com"}],"tags":["nvd"],"ingestedAt":"2026-10-09T22:14:52.101Z","slug":"CVE-2026-108263","body":"## Overview\n\nAstron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed. LocalExecutor supplies complete Python builtins to dynamic code execution without the documented sandbox restrictions. An authenticated low-privilege tenant can execute code as root in the core-workflow container and use shared service and database credentials to bypass application-level tenant checks, read or modify other tenants' data, and disrupt shared services. This issue is fixed in version 1.1.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":54.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}