Vulnerability  ·  2026-08-25

Bytebot AI agent — Agent Execution Workflow infinite loop enables remote denial-of-service

VulnerabilityLow impactGlobalCVE-2026-78250
NVD published CVE-2026-78250 (CVSS 4.3 Medium) on 2026-08-24, describing a remotely-triggerable infinite loop in Bytebot's agent execution workflow with a publicly available exploit report.
Illustrates the emerging 'agent-loop budget exhaustion' DoS pattern affecting early-stage autonomous agent frameworks, but the affected project's low maturity (v0.0.1) and DoS-only impact keep the practical blast radius small.
An unspecified function within Bytebot's Agent Execution Workflow component can be manipulated remotely to trigger an infinite loop, exhausting compute/budget resources (a step/loop-budget exhaustion DoS) without requiring authentication.
outlookgp/bytebot-ai bytebot 0.0.1
No patched version identified in the record; implement step/loop budget caps and execution timeouts as compensating controls until a fix ships.
NVD - CVE-2026-78250GitHub PoC - outlookgp/CVE
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →