CVE-2026-73081: Activepieces: Remote Code Execution via Command Injection in Code Step Name
Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, the worker's code-compilation pipeline builds the on-disk path for a Code step from the step's name and passes that path to a shell-invoked build command. A step name containing shell metacharacters can break out of the intended build invocation and execute arbitrary commands during compilation before any code sandbox is created. An authenticated user with permission to create or edit a flow can execute commands as the worker process user, read and write the worker filesystem, exfiltrate environment secrets, and reach internal services available to the worker. This issue is fixed in version 0.80.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Activepiecesto a version that resolves this vulnerability.Fixed in 0.80.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73081?
CVE-2026-73081 has a risk score of 70, indicating a high severity level.
How do I fix CVE-2026-73081?
To mitigate CVE-2026-73081, update Activepieces to version 0.80.0 or later.
What type of vulnerability is CVE-2026-73081?
CVE-2026-73081 is an OS Command Injection vulnerability affecting the Activepieces platform.
What impact does CVE-2026-73081 have on Activepieces?
CVE-2026-73081 allows for remote code execution through command injection in the code step name.
Which versions of Activepieces are affected by CVE-2026-73081?
CVE-2026-73081 affects all versions of Activepieces prior to 0.80.0.