CVE-2026-108263
Received Received - Intake

Astron Agent Remote Code Execution Vulnerability

Vulnerability report for CVE-2026-108263, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed. LocalExecutor supplies complete Python builtins to dynamic code execution without the documented sandbox restrictions. An authenticated low-privilege tenant can execute code as root in the core-workflow container and use shared service and database credentials to bypass application-level tenant checks, read or modify other tenants' data, and disrupt shared services. This issue is fixed in version 1.1.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
iflytek astron-agent < 1.1.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
CWE-1392 The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.
CWE-95 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").
CWE-653 The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Astron Agent before version 1.1.2 allows authenticated low-privilege users to execute arbitrary Python code as root in the core-workflow container due to improper sandboxing. The vulnerability occurs when CODE_EXEC_TYPE is not set, defaulting to LocalExecutor which provides full Python builtins without restrictions.

Detection Guidance

Check Astron Agent version with: curl -s http://<target>/version | grep version. If version is below 1.1.2, the system is vulnerable. Inspect /console-api/workflow/code/run and /workflow/v1/run endpoints for unauthorized access attempts or unusual code execution patterns.

Impact Analysis

An attacker could gain root access to the container, read or modify data from other tenants, bypass application-level security checks, and disrupt shared services. This requires only low-privilege authentication to the platform.

Compliance Impact

This vulnerability likely violates data protection requirements in GDPR and HIPAA by enabling unauthorized access to sensitive tenant data and potential data breaches. It compromises confidentiality, integrity, and availability controls required by these regulations.

Mitigation Strategies

Upgrade Astron Agent to version 1.1.2 or later immediately. Restrict network access to /console-api/workflow/code/run and /workflow/v1/run endpoints. Review container permissions and ensure LocalExecutor is not exposed to untrusted users. Rotate shared service and database credentials if compromised.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108263. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart