LocalExecutor Vulnerability in Astron Agent Affects Workflow Processes
CVE-2026-108263
9.9CRITICAL
What is CVE-2026-108263?
The Astron Agent workflow platform possesses a significant vulnerability that allows a low-privilege authenticated user to execute arbitrary code as root. This occurs due to the default execution path in the platform's code-node, which utilizes LocalExecutor without adequate sandboxing. The vulnerability arises when the CODE_EXEC_TYPE is not set to explicitly restrict execution, leading to potential bypass of application-level tenant checks. Consequently, attackers may gain access to shared services and databases, enabling unauthorized data manipulation across different tenant environments. This issue has been resolved in Astron Agent version 1.1.2.
Affected Version(s)
astron-agent < 1.1.2
