AutoAgent vulnerability

AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host workspace directories.

Published 5 Sep 2026Updated 5 Sep 20265 sources
CVSS 9.3

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.