Vulnerability  ·  2026-10-11

Astron Agent default LocalExecutor code-node path → cross-tenant RCE as root (CVSS 9.9)

VulnerabilityHigh impactGlobalCVE-2026-108263
Until 1.1.2, the default workflow code-node path selected LocalExecutor, which supplies complete Python builtins to dynamically executed code without the documented sandbox restrictions. NVD verified via REST API (published 2026-10-09, GitHub security advisory; CVSS 9.9 CWE-95/CWE-306/CWE-653/CWE-863).
Agentic workflow platforms are exactly the 'model output drives code execution' surface where sandbox escapes matter; this is a direct cross-tenant server-side code-execution primitive in an AI agent orchestration platform, not a theoretical prompt-injection paper — an attacker only needs a low-privilege tenant account.
An authenticated low-privileged tenant submits code through the default workflow code-node path; because CODE_EXEC_TYPE is not set, LocalExecutor runs the code with full Python builtins in the core-workflow container as root, letting the attacker use shared credentials to bypass tenant checks, read/modify other tenants' data, and disrupt shared services.
iflytek/astron-agent < 1.1.2 (default workflow code-node path via /console-api/workflow/code/run and /workflow/v1/run)
Upgrade to 1.1.2 (commit 848daba03e5e045435863815be7ab6dfbcefc18f; GHSA-mh3w-4q3f-2fg5). Enforce an explicit, sandboxed executor for code nodes.
NVD CVE-2026-108263NVD REST APIGitHub advisory GHSA-mh3w-4q3f-2fg5
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →