


Perceptive Security
SOC/SIEM Consultancy

AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipelin…
Published:
28 april 2026 om 22:00:00
Alert date:
29 april 2026 om 20:02:14
Source:
nvd.nist.gov
Web Technologies
AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs and POST /api/runs/validate endpoints. Attackers can induce requests to the local AgentFlow API to load and execute existing Python pipeline files on disk, resulting in code execution in the context of the user running AgentFlow. The vulnerability is present in the API endpoints that process pipeline path parameters without proper validation. This allows for local file inclusion and execution of Python code on the server. The impact is high as it allows arbitrary code execution with the privileges of the AgentFlow service.
Technical details
Mitigation steps:
Affected products:
AgentFlow
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7466
https://github.com/berabuddies/agentflow/pull/18
https://github.com/berabuddies/agentflow/pull/18/changes/7e61b6ce846b3d700456e4874394dc868905a9f2
https://www.vulncheck.com/advisories/agentflow-arbitrary-python-pipeline-execution-via-pipeline-path
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
