OS Command Injection Vulnerability in SkyworkAI DeepResearchAgent
CVE-2025-8667
What is CVE-2025-8667?
A security flaw exists in the SkyworkAI DeepResearchAgent affecting its tools.py file, specifically in the from_code/from_dict/from_mcp functions. This vulnerability allows an attacker to execute arbitrary operating system commands remotely, posing a significant risk to systems using this software. Given the continuous delivery model employed by SkyworkAI, identifying the specific versions affected can be challenging, as there are no clear version details on affected or patched releases. Early attempts to contact the vendor regarding this vulnerability went unanswered, raising concerns over the responsiveness to security issues.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DeepResearchAgent 08eb7f8eb9505d0094d75bb97ff7dacc3fa3bbf2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
