CVE-2026-108263: Iflytek Astron-Agent

Critical severity, CVSS 9.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed. LocalExecutor supplies complete Python builtins to dynamic code execution without the documented sandbox restrictions. An authenticated low-privilege tenant can execute code as root in the core-workflow container and use shared service and database credentials to bypass application-level tenant checks, read or modify other tenants' data, and disrupt shared services. This issue is fixed in version 1.1.2.

Affected products

  • Iflytek Astron-Agent: before 1.1.2 (fixed in 1.1.2)

Published 2026-10-09. Last modified 2026-10-09.