Releases76
Frequency4 days 11 hours
Last Release
Stars14.6K
Eigent: The Open Source Cowork Desktop - Local and Free Alternative to Claude Cowork and Codex

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
< 0.0.789.8 CRITICAL

Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allows arbitrary code execution from fork pull requests with repository write permissions. The vulnerable workflow uses pull_request_target trigger combined with checkout of untrusted PR code. An attacker can exploit this to steal credentials, post comments, push code, or create releases.

= 0.0.609.8 CRITICAL

Eigent is a multi-agent Workforce. In version 0.0.60, a 1-click Remote Code Execution (RCE) vulnerability has been identified in Eigent. This vulnerability allows an attacker to execute arbitrary code on the victim's machine or server through a specific interaction (1-click). This issue has been patched in version 0.0.61.