PT-2026-71875 · Unknown · Agenticseek

·

CVE-2026-72776

·

Published

2026-08-13

·

Updated

2026-08-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AgenticSeek version fc242c7
Description An unauthenticated remote code execution issue exists that allows network-adjacent attackers to execute arbitrary commands. By submitting crafted queries to the unprotected 'POST /query' API endpoint, an attacker can trigger the autonomous agent to generate and execute shell commands. This occurs through the BashInterpreter using subprocess.Popen with shell=True and safety=False, which bypasses an incomplete command blocklist to achieve full host-level code execution.
Recommendations For version fc242c7, restrict access to the 'POST /query' API endpoint or disable the BashInterpreter function to prevent unauthorized command execution.

Exploit

Fix

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72776

Affected Products

Agenticseek