Vulnerabilities
Vulnerable Software
Eigent:  >> Eigent  >> 0.0.60  Security Vulnerabilities
Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allows arbitrary code execution from fork pull requests with repository write permissions. The vulnerable workflow uses pull_request_target trigger combined with checkout of untrusted PR code. An attacker can exploit this to steal credentials, post comments, push code, or create releases.
CVSS Score
9.8
EPSS Score
0.001
Published
2026-01-13
Eigent is a multi-agent Workforce. In version 0.0.60, a 1-click Remote Code Execution (RCE) vulnerability has been identified in Eigent. This vulnerability allows an attacker to execute arbitrary code on the victim's machine or server through a specific interaction (1-click). This issue has been patched in version 0.0.61.
CVSS Score
9.8
EPSS Score
0.004
Published
2025-12-27


Contact Us

Shodan ® - All rights reserved