Impact
Astron Agent, an agentic workflow platform, contains a configuration flaw that allows a tenant with low‑privilege credentials to execute arbitrary Python code with full system rights. The flaw arises because the default CODE_EXEC_TYPE selects a LocalExecutor that does not enforce sandbox restrictions, giving the executing code unrestricted access to the core‑workflow container and shared database credentials. This enables attackers to run code as root, read or modify data belonging to other tenants, and disrupt shared services, effectively achieving remote code execution with cross‑tenant authority.
Affected Systems
All installations of iflytek Astron Agent earlier than version 1.1.2 are affected. The vulnerability exists across all releases that ship with the default /console‑api/workflow/code/run and /workflow/v1/run endpoints before the 1.1.2 release.
Risk and Exploitability
The CVSS score of 9.9 marks this a critical vulnerability, and although an EPSS score is not available, the vulnerability is actively exploitable by authenticated users who can request workflow execution. The lack of CISA KEV listing does not reduce the risk; the issue remains unpatched in many environments. Attackers can efficiently launch the exploit by employing the tenant's existing API access to trigger the code node, bypassing application‑level tenant checks and achieving root level execution within the container.
OpenCVE Enrichment