CVE-2026-108263
Astron Agent: Unsandboxed code-node leads to cross-tenant RCE
Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed. LocalExecutor supplies complete Python builtins to dynamic code execution without the documented sandbox restrictions. An authenticated low-privilege tenant can execute code as root in the core-workflow container and use shared service and database credentials to bypass application-level tenant checks, read or modify other tenants' data, and disrupt shared services. This issue is fixed in version 1.1.2.
| CWE | CWE-95 CWE-306 CWE-653 CWE-863 CWE-1392 |
| Vendor | iflytek |
| Product | astron-agent |
| Published | Oct 9, 2026 |
Get instant alerts for iflytek astron-agent
Be the first to know when new critical vulnerabilities affecting iflytek astron-agent are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H