CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-72776 — AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution v...

·Source: NIST NVD

Updated:

Executive Summary

AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS. Attackers can send unauthenticated HTTP requests that cause the autonomous agent to generate and execute shell commands

Analysis

AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS. Attackers can send unauthenticated HTTP requests that cause the autonomous agent to generate and execute shell commands through BashInterpreter using subprocess.Popen with shell=True and safety=False, bypassing the incomplete command blocklist to achieve full host-level code execution. CVSS Score: 9.8. Published: 2026-08-13T22:17:23.340.

Indicators of Compromise (1)

CVE (1)
CVE-2026-72776
Source Attribution

Originally published by NIST NVD on Aug 13, 2026. Verified by: NIST.

Related Threats