Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-108263: Astron Agent lets tenant run code as root
CVE-2026-108263 · published today
Summary
The Astron Agent platform (versions before 1.1.2) lets a low‑privilege user run unrestricted Python code on the server. This can let them act as the system administrator, read or change other customers' data, and interfere with shared services. Upgrade to version 1.1.2 or later to apply the fix.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| iflytek | astron-agent | < 1.1.2 |
Original advisory text
Astron Agent: Unsandboxed code-node leads to cross-tenant RCE
Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed. LocalExecutor supplies complete Python builtins to dynamic code execution without the documented sandbox restrictions. An authenticated low-privilege tenant can execute code as root in the core-workflow container and use shared service and database credentials to bypass application-level tenant checks, read or modify other tenants' data, and disrupt shared services. This issue is fixed in version 1.1.2.
References
- https://github.com/iflytek/astron-agent/commit/848daba03e5e045435863815be7ab6dfb... x_refsource_MISC
- https://github.com/iflytek/astron-agent/pull/1650 x_refsource_MISC
- https://github.com/iflytek/astron-agent/pull/1651 x_refsource_MISC
- https://github.com/iflytek/astron-agent/security/advisories/GHSA-mh3w-4q3f-2fg5 x_refsource_CONFIRM
- https://github.com/iflytek/astron-agent/commit/ebf074a431e96da0ad9e0a56409d3d2da... x_refsource_MISC
- https://github.com/iflytek/astron-agent/releases/tag/v1.1.2 x_refsource_MISC
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit (estimated)
- Gives an attacker full control (estimated)
Type
CWE-95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
CWE-306Missing Authentication for Critical Function
CWE-653Improper Isolation or Compartmentalization
CWE-863Incorrect Authorization
CWE-1392Use of Default Credentials
Timeline
Published9 Oct 2026
Updated9 Oct 2026
First seen9 Oct 2026
Track software like this
Free during beta