Summary
CVE-2026-72776 is a critical unauthenticated remote code execution (RCE) vulnerability in AgenticSeek, an open-source autonomous AI agent platform, caused by an unprotected API endpoint combined with unsafe shell command execution. Any attacker with network access to the exposed service can submit a crafted request and achieve full host-level command execution without any credentials. The flaw is tracked as CWE-306 (Missing Authentication for Critical Function) and carries a critical severity rating.
Technical details
- Root cause: The AgenticSeek backend exposes a
POST /queryAPI endpoint with no authentication or access control, bound to0.0.0.0:7777and configured with wildcard CORS, making it reachable from any origin on the network. - Trigger conditions: A request to
/querycauses the agent to generate and execute shell commands via itsBashInterpretertool, which invokessubprocess.Popenwithshell=True; command filtering relies on an incomplete blocklist that can be bypassed. - Attack vector: Network (unauthenticated, no user interaction required) — an attacker simply sends a crafted query to the exposed endpoint.
- Impact: Full compromise of confidentiality, integrity, and availability of the host running AgenticSeek, as arbitrary OS commands can be executed with the privileges of the service.
Affected software
- Fosowl/agenticSeek — all commits up to and including
fc242c7(prior to fix commitf1eb2cfc721f8a21dd16a8b048a9ca89f3259f6f)
Severity
- CVSS v3.1 Base Score: 9.8 (Critical) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v4.0 Base Score: 9.3 (Critical) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Update to a version of AgenticSeek including commit
f1eb2cfc721f8a21dd16a8b048a9ca89f3259f6f(merged via PR #534) or later, which addresses the authentication and command-execution issues. - If no patch can be applied immediately:
- Do not bind the AgenticSeek API to
0.0.0.0; restrict it tolocalhostor an internal-only interface. - Place the service behind a reverse proxy or gateway that enforces authentication before requests reach
/query. - Remove or restrict the wildcard CORS configuration to trusted origins only.
- Use network-level controls (firewall rules, VPN/segmentation) to block internet exposure of port 7777 and any AgenticSeek management interfaces.
- Do not bind the AgenticSeek API to

