Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Iflytek
Iflytek astron-agent |
|
| Vendors & Products |
Iflytek
Iflytek astron-agent |
Fri, 09 Oct 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed. LocalExecutor supplies complete Python builtins to dynamic code execution without the documented sandbox restrictions. An authenticated low-privilege tenant can execute code as root in the core-workflow container and use shared service and database credentials to bypass application-level tenant checks, read or modify other tenants' data, and disrupt shared services. This issue is fixed in version 1.1.2. | |
| Title | Astron Agent: Unsandboxed code-node leads to cross-tenant RCE | |
| Weaknesses | CWE-1392 CWE-306 CWE-653 CWE-863 CWE-95 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T20:47:38.407Z
Reserved: 2026-10-09T17:33:15.410Z
Link: CVE-2026-108263
No data.
Status : Received
Published: 2026-10-09T21:17:04.527
Modified: 2026-10-09T21:17:04.527
Link: CVE-2026-108263
No data.
OpenCVE Enrichment
Updated: 2026-10-09T22:30:13Z