CVE-2026-108263 PUBLISHED

Astron Agent: Unsandboxed code-node leads to cross-tenant RCE

Assigner: GitHub_M
Reserved: 09.10.2026 Published: 09.10.2026 Updated: 09.10.2026

Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed. LocalExecutor supplies complete Python builtins to dynamic code execution without the documented sandbox restrictions. An authenticated low-privilege tenant can execute code as root in the core-workflow container and use shared service and database credentials to bypass application-level tenant checks, read or modify other tenants' data, and disrupt shared services. This issue is fixed in version 1.1.2.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor iflytek
Product astron-agent
Versions
  • Version < 1.1.2 is affected

References

Problem Types

  • CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') CWE
  • CWE-306: Missing Authentication for Critical Function CWE
  • CWE-653: Improper Isolation or Compartmentalization CWE
  • CWE-863: Incorrect Authorization CWE
  • CWE-1392: Use of Default Credentials CWE