Skip to content
LatestBlock Object Injection in Booklovers Theme by Verifying Version Before 2.13.1
Vulnerabilities

Upgrade Astron Agent to 1.1.2 to Block Root Code Execution

A critical flaw in Astron Agent versions before 1.1.2 allows authenticated tenants to run arbitrary code as root, risking full system compromise.

Upgrade Astron Agent to 1.1.2 to Block Root Code Execution
Illustration: Vector Update

Key points

  • CVE-2026-108263 carries a CVSS score of 9.9, rated Critical by the National Vulnerability Database.
  • The flaw exists in Astron Agent versions prior to 1.1.2 and affects the default workflow code execution engine.
  • Attackers can execute code as root, bypass tenant isolation, and access shared service credentials.

System administrators running Astron Agent must update to version 1.1.2 immediately. The National Vulnerability Database lists CVE-2026-108263 as a Critical severity issue with a perfect CVSS score of 9.9. This vulnerability allows authenticated users with low privileges to execute arbitrary code with root permissions. The flaw compromises the core isolation mechanisms that protect multi-tenant environments.

In plain English

Astron Agent is designed to help organizations build and run AI agents. Before version 1.1.2, the platform’s default settings for handling code within workflows were unsafe. When the configuration variable CODE_EXEC_TYPE was not explicitly changed, the system used a component called LocalExecutor. This component ran Python code with full access to built-in functions. It did not apply the sandbox restrictions that the documentation promised.

The background

The vulnerability stems from how the platform handles code execution nodes. According to the NVD record, the endpoints /console-api/workflow/code/run and /workflow/v1/run trigger this behavior. The specific code in core/workflow/engine/nodes/code/code_node.py selects LocalExecutor by default. This selection bypasses necessary security constraints. An attacker does not need to break into the system from the outside. They only need valid login credentials for a low-privilege tenant account. Once logged in, they can submit malicious code through the workflow interface.

What changes now

The successful exploitation of this flaw grants an attacker root access within the core-workflow container. With root privileges, the attacker gains control over the container’s operating system. They can then access shared service credentials and database connections. This allows them to bypass application-level checks that separate different tenants. Attackers can read, modify, or delete data belonging to other users. They can also disrupt shared services that rely on the same infrastructure. Version 1.1.2 fixes this issue by correcting the default execution behavior.

What to do and how to stay safe: Astron Agent

  • Check your current Astron Agent version and upgrade to 1.1.2 or later if you are running an older release.
  • Review workflow configurations to ensure CODE_EXEC_TYPE is explicitly set and not relying on default values.
  • Audit access logs for unauthorized code execution attempts or unusual workflow activity from tenant accounts.
  • Isolate Astron Agent containers to limit the blast radius if a compromise occurs before patching.

Step-by-step guide: Risk-Based Vulnerability Management: Benefits, Limits, and Reality

General security guidance from the Vector Update newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

What is CVE-2026-108263?

CVE-2026-108263 is a critical vulnerability in Astron Agent that allows low-privilege tenants to execute code as root due to unsafe default settings in the LocalExecutor.

Which versions of Astron Agent are affected?

All versions of Astron Agent prior to 1.1.2 are affected by this vulnerability, as the fix was introduced in version 1.1.2.

How severe is this vulnerability?

The National Vulnerability Database rates CVE-2026-108263 as Critical with a CVSS score of 9.9, indicating a high risk of successful exploitation.

Sources

  1. CVE Program
Astron AgentCVE-2026-108263iflytekLocalExecutorCVSS 9.9

Related stories