{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-108263","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2026-10-09T17:33:15.410Z","datePublished":"2026-10-09T20:47:38.407Z","dateUpdated":"2026-10-09T20:47:38.407Z"},"containers":{"cna":{"title":"Astron Agent: Unsandboxed code-node leads to cross-tenant RCE","problemTypes":[{"descriptions":[{"cweId":"CWE-95","lang":"en","description":"CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-306","lang":"en","description":"CWE-306: Missing Authentication for Critical Function","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-653","lang":"en","description":"CWE-653: Improper Isolation or Compartmentalization","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-863","lang":"en","description":"CWE-863: Incorrect Authorization","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-1392","lang":"en","description":"CWE-1392: Use of Default Credentials","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"name":"https://github.com/iflytek/astron-agent/security/advisories/GHSA-mh3w-4q3f-2fg5","tags":["x_refsource_CONFIRM"],"url":"https://github.com/iflytek/astron-agent/security/advisories/GHSA-mh3w-4q3f-2fg5"},{"name":"https://github.com/iflytek/astron-agent/pull/1650","tags":["x_refsource_MISC"],"url":"https://github.com/iflytek/astron-agent/pull/1650"},{"name":"https://github.com/iflytek/astron-agent/pull/1651","tags":["x_refsource_MISC"],"url":"https://github.com/iflytek/astron-agent/pull/1651"},{"name":"https://github.com/iflytek/astron-agent/commit/848daba03e5e045435863815be7ab6dfbcefc18f","tags":["x_refsource_MISC"],"url":"https://github.com/iflytek/astron-agent/commit/848daba03e5e045435863815be7ab6dfbcefc18f"},{"name":"https://github.com/iflytek/astron-agent/commit/ebf074a431e96da0ad9e0a56409d3d2da15eae36","tags":["x_refsource_MISC"],"url":"https://github.com/iflytek/astron-agent/commit/ebf074a431e96da0ad9e0a56409d3d2da15eae36"},{"name":"https://github.com/iflytek/astron-agent/releases/tag/v1.1.2","tags":["x_refsource_MISC"],"url":"https://github.com/iflytek/astron-agent/releases/tag/v1.1.2"}],"affected":[{"vendor":"iflytek","product":"astron-agent","versions":[{"version":"< 1.1.2","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2026-10-09T20:47:38.407Z"},"descriptions":[{"lang":"en","value":"Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed. LocalExecutor supplies complete Python builtins to dynamic code execution without the documented sandbox restrictions. An authenticated low-privilege tenant can execute code as root in the core-workflow container and use shared service and database credentials to bypass application-level tenant checks, read or modify other tenants' data, and disrupt shared services. This issue is fixed in version 1.1.2."}],"source":{"advisory":"GHSA-mh3w-4q3f-2fg5","discovery":"UNKNOWN"}}}}