LocalExecutor Vulnerability in Astron Agent Affects Workflow Processes
CVE-2026-108263

9.9CRITICAL

Key Information:

Vendor

Iflytek

Vendor
CVE Published:
9 October 2026

What is CVE-2026-108263?

The Astron Agent workflow platform possesses a significant vulnerability that allows a low-privilege authenticated user to execute arbitrary code as root. This occurs due to the default execution path in the platform's code-node, which utilizes LocalExecutor without adequate sandboxing. The vulnerability arises when the CODE_EXEC_TYPE is not set to explicitly restrict execution, leading to potential bypass of application-level tenant checks. Consequently, attackers may gain access to shared services and databases, enabling unauthorized data manipulation across different tenant environments. This issue has been resolved in Astron Agent version 1.1.2.

Affected Version(s)

astron-agent < 1.1.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.