PT-2026-71875 · Unknown · Agenticseek
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AgenticSeek version fc242c7
Description
An unauthenticated remote code execution issue exists that allows network-adjacent attackers to execute arbitrary commands. By submitting crafted queries to the unprotected 'POST /query' API endpoint, an attacker can trigger the autonomous agent to generate and execute shell commands. This occurs through the
BashInterpreter using subprocess.Popen with shell=True and safety=False, which bypasses an incomplete command blocklist to achieve full host-level code execution.Recommendations
For version fc242c7, restrict access to the 'POST /query' API endpoint or disable the
BashInterpreter function to prevent unauthorized command execution.Exploit
Fix
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Agenticseek