CVE-2026-5584 is a code injection vulnerability affecting Fosowl agenticSeek version 0.1.0, specifically in the PyInterpreter.execute function within the query endpoint component. This vulnerability allows remote attackers to inject and execute arbitrary code without requiring authentication or user interaction. The vulnerability carries a CVSS 3.1 score of 7.3 (HIGH), indicating significant risk with a network-based attack vector, low complexity, and no privilege requirements. Successful exploitation could result in confidentiality, integrity, and availability impacts. The FAUCET Risk Score of 47.0/100 reflects a moderate-to-high concern level. Regarding exploitation status, while proof-of-concept code has been publicly disclosed, the vulnerability is not currently tracked on the CISA Known Exploited Vulnerabilities (KEV) catalog and shows no active exploitation indicators. The vendor was notified early but provided no response. Given the public disclosure and the nature of the vulnerability, organizations running Fosowl agenticSeek 0.1.0 should prioritize patching or upgrading to a fixed version immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.1.0CPE matchmatch criteria | cpe:2.3:a:fosowl:agenticseek:0.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.