Agions Taskflow-AI Command Injection Vulnerability in MCP Tool Execution

Vulnerability

A command injection vulnerability has been identified in Agions Taskflow-AI versions through 2.1.8. The issue resides in the MCP server handlers and executor components, specifically within the 'terminal_execute' tool, which is not publicly listed but can be invoked by attackers. The vulnerability allows for arbitrary OS command execution by exploiting insufficient input validation, potentially leading to full host compromise.

Impact

Exploitation of this vulnerability allows for arbitrary OS command execution, which can result in full host compromise, including unauthorized data access, modification of system integrity, and disruption of services.

Reproduction

To reproduce this vulnerability, invoke the MCP 'CallTool' handler with a request that includes a crafted command string for the 'terminal_execute' tool. The command injection can be verified by executing a command that returns a visible output, such as 'id', which will be injected and executed on the server.

Remediation

Users are advised to upgrade to Agions Taskflow-AI version 2.1.9 or later, where this vulnerability has been fixed.

Added: Apr 9, 2026, 2:26 AM
Updated: Apr 9, 2026, 2:26 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.3
remediation
0.0
relevance
5.6
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.