{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/agenticseek/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-72776"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AgenticSeek"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAgenticSeek (commit fc242c7) contains a critical unauthenticated remote code execution vulnerability. The application exposes an API endpoint at POST /query which is bound to all network interfaces (0.0.0.0:7777) and configured with wildcard Cross-Origin Resource Sharing (CORS). The vulnerability stems from the application's reliance on the BashInterpreter component, which executes user-supplied queries using subprocess.Popen with shell=True and safety=False. Because the internal command blocklist is incomplete and easily bypassed, a network-adjacent attacker can submit crafted HTTP POST requests to trigger the execution of arbitrary operating system commands on the host. This vulnerability allows for full system compromise without any prior authentication or authorization.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS v3.1 base score of 9.8, indicating the highest level of severity. Successful exploitation results in unauthenticated, host-level code execution. In environments where AgenticSeek is deployed with network-wide accessibility, any attacker with network adjacency can gain immediate control over the host machine, leading to potential data exfiltration, lateral movement within the network, or the installation of persistent malicious software.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eRestrict network access to the AgenticSeek API endpoint at port 7777 to trusted management networks only, ensuring it is not reachable from untrusted segments or the public internet.\u003c/li\u003e\n\u003cli\u003eImplement strict authentication middleware for the /query API endpoint to ensure all requests are validated before being processed by the agent.\u003c/li\u003e\n\u003cli\u003eUpdate the AgenticSeek implementation to utilize subprocess.run with shell=False and pass arguments as a list to prevent shell metacharacter injection.\u003c/li\u003e\n\u003cli\u003eReplace the existing command blocklist with a robust, allowlist-based validation mechanism that strictly defines permissible commands and parameters.\u003c/li\u003e\n\u003cli\u003eDeploy the suggested Sigma rule to monitor for suspicious POST requests targeting the /query endpoint that contain shell metacharacters.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-14T00:05:24Z","date_published":"2026-08-14T00:05:24Z","id":"https://feed.craftedsignal.io/briefs/2026-08-agenticseek-rce/","summary":"AgenticSeek commit fc242c7 is vulnerable to unauthenticated remote code execution via a misconfigured /query API endpoint that allows arbitrary shell command injection through the BashInterpreter module.","title":"Unauthenticated RCE in AgenticSeek via Command Injection","url":"https://feed.craftedsignal.io/briefs/2026-08-agenticseek-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - AgenticSeek","version":"https://jsonfeed.org/version/1.1"}