CVE-2026-7466Disclosure

LOWCVSS 7.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs and POST /api/runs/validate endpoints. Attackers can induce requests to the local AgentFlow API to load and execute existing Python pipeline files on disk, resulting in code execution in the context of the user running AgentFlow.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-29: 2Technical Details · 2026-04-29: 204-29
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7466 Arbitrary Code Execution in AgentFlow via User-Controlled Pipeline Path Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7466

    Post summary

    The post announces CVE‑2026‑7466, detailing an arbitrary code execution flaw in AgentFlow triggered by a user‑controlled pipeline path parameter, with no mention of exploits, patches, or active exploitation.

    0000066
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7466 AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path p… https://www.cve.org/CVERecord?id=CVE-2026-7466

    Post summary

    The post announces CVE‑2026‑7466 as an arbitrary code execution flaw in AgentFlow, describing how attackers can run local Python pipeline files, but provides no evidence of exploitation, PoC, or patch status.

    0000085
    57.3K followersView on X

Explore more