Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-108263— Astron Agent: Unsandboxed code-node leads to cross-tenant RCE

Quick assessment

Affected
iflytek astron-agent
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Astron Agent 是一个用于构建和运行 AI 智能体(AI agents)的代理工作流平台。在版本 1.1.2 之前,当未显式更改 CODE_EXEC_TYPE 环境变量时,通过 和 路径执行的默认工作流代码节点会使用 中的 LocalExecutor。LocalExecutor 在未遵循文档所述沙箱限制的情况下,向动态代码执行提供了完整的 Python 内置函数支持。因此,拥有认证的低权限租户可以以 root 用户身份在核心工作流容器中执行任意代码,并利用共享服务和数据库凭据绕过应用层级的租户隔离检查,从

CVSS 9.9 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-108263

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Astron Agent: Unsandboxed code-node leads to cross-tenant RCE
Source: CVE Program / CVE List V5
Vulnerability Description
Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed. LocalExecutor supplies complete Python builtins to dynamic code execution without the documented sandbox restrictions. An authenticated low-privilege tenant can execute code as root in the core-workflow container and use shared service and database credentials to bypass application-level tenant checks, read or modify other tenants' data, and disrupt shared services. This issue is fixed in version 1.1.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
动态执行代码中指令转义处理不恰当(Eval注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
iflytek astron-agent < 1.1.2 -

II. Public POCs for CVE-2026-108263

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-108263

请登录查看更多情报信息。

Other References for CVE-2026-108263 (6)

Same Patch Batch · iflytek · 2026-10-09 · 3 CVEs total

CVE-2026-108160 7.5 HIGH AstronRPA through 1.1.6 Unsigned Update Installation via Plain-HTTP Feed
CVE-2026-108159 7.5 HIGH AstronRPA through 1.1.6 RCE via Smart-Component Chat XSS and IPC Bridge

IV. Related Vulnerabilities

V. Comments for CVE-2026-108263

No comments yet


Leave a comment