Product
AgenticSeek commit fc242c7 is vulnerable to unauthenticated remote code execution via a misconfigured /query API endpoint that allows arbitrary shell command injection through the BashInterpreter module.