CVE-2026-7466
HIGHAgentFlow Arbitrary Python Pipeline Execution via pipeline_path
Title source: cnaDescription
AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs and POST /api/runs/validate endpoints. Attackers can induce requests to the local AgentFlow API to load and execute existing Python pipeline files on disk, resulting in code execution in the context of the user running AgentFlow.
References (3)
Core 3
Core References
issue-tracking
https://github.com/berabuddies/agentflow/pull/18
issue-tracking
https://github.com/berabuddies/agentflow/pull/18/changes/7e61b6ce846b3d700456e4874394dc868905a9f2
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/agentflow-arbitrary-python-pipeline-execution-via-pipeline-path
Scores
CVSS v3
8.8
EPSS
0.0034
EPSS Percentile
26.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (1)
berabuddies/AgentFlow
< 1667fa3
Published
Apr 29, 2026
Tracked Since
Apr 30, 2026