What happened
Until 1.1.2, the default workflow code-node path selected LocalExecutor, which supplies complete Python builtins to dynamically executed code without the documented sandbox restrictions. NVD verified via REST API (published 2026-10-09, GitHub security advisory; CVSS 9.9 CWE-95/CWE-306/CWE-653/CWE-863).
Why it matters
Agentic workflow platforms are exactly the 'model output drives code execution' surface where sandbox escapes matter; this is a direct cross-tenant server-side code-execution primitive in an AI agent orchestration platform, not a theoretical prompt-injection paper — an attacker only needs a low-privilege tenant account.
Attack vector
An authenticated low-privileged tenant submits code through the default workflow code-node path; because CODE_EXEC_TYPE is not set, LocalExecutor runs the code with full Python builtins in the core-workflow container as root, letting the attacker use shared credentials to bypass tenant checks, read/modify other tenants' data, and disrupt shared services.
Affected systems
iflytek/astron-agent < 1.1.2 (default workflow code-node path via /console-api/workflow/code/run and /workflow/v1/run)
Mitigation
Upgrade to 1.1.2 (commit 848daba03e5e045435863815be7ab6dfbcefc18f; GHSA-mh3w-4q3f-2fg5). Enforce an explicit, sandboxed executor for code nodes.