
Astron Agent (CVE-2026-108263, CVSS 9.9): through 1.1.1 the default Code-node path documents RestrictedPython, but RestrictedPython isn't a dependency — any workflow author gets root Python and cross-tenant DB access. Fixed in 1.1.2. https://github.com/iflytek/astron-agent/security/advisories/GHSA-mh3w-4q3f-2fg5
