PT-2026-60838 · Unknown · Agentic-Flow

CVE-2026-58195

·

Published

2026-06-19

·

Updated

2026-07-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Agentic-Flow versions prior to 2.0.14
Description An AI agent orchestration platform fails to properly sanitize tool parameters before passing them to the execSync() function. This allows an attacker to influence parameters such as agent, task, name, language, and agentdb, which are interpolated directly into shell command strings. Consequently, this can lead to arbitrary OS command execution with the privileges of the MCP server user. The issue affects several server tools, including those in src/mcp/standalone-stdio.ts, src/mcp/fastmcp/servers/claude-flow-sdk.ts, src/mcp/fastmcp/servers/stdio-full.ts, src/mcp/fastmcp/servers/http-streaming-updated.ts, src/mcp/fastmcp/servers/http-sse.ts, src/mcp/fastmcp/servers/poc-stdio.ts, src/mcp/fastmcp/tools/agent/{execute,list,parallel}.ts, src/mcp/fastmcp/tools/swarm/orchestrate.ts, and src/mcp/fastmcp/tools/hooks/pretrain.ts.
Recommendations Update to version 2.0.14.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58195
GHSA-VCV2-R9JH-99M5

Affected Products

Agentic-Flow