top of page
perceptive_background_267k.jpg

AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipelin…

Published:

28 april 2026 om 22:00:00

Alert date:

29 april 2026 om 20:02:14

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs and POST /api/runs/validate endpoints. Attackers can induce requests to the local AgentFlow API to load and execute existing Python pipeline files on disk, resulting in code execution in the context of the user running AgentFlow. The vulnerability is present in the API endpoints that process pipeline path parameters without proper validation. This allows for local file inclusion and execution of Python code on the server. The impact is high as it allows arbitrary code execution with the privileges of the AgentFlow service.

Technical details

Mitigation steps:

Affected products:

AgentFlow

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page