eigent-ai/eigent
Releases76
Frequency4 days 11 hours
Last Release
Stars14.6K
Eigent: The Open Source Cowork Desktop - Local and Free Alternative to Claude Cowork and Codex
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| < 0.0.78 | 9.8 CRITICAL | — | ||
Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allows arbitrary code execution from fork pull requests with repository write permissions. The vulnerable workflow uses pull_request_target trigger combined with checkout of untrusted PR code. An attacker can exploit this to steal credentials, post comments, push code, or create releases. | ||||
| = 0.0.60 | 9.8 CRITICAL | — | ||
Eigent is a multi-agent Workforce. In version 0.0.60, a 1-click Remote Code Execution (RCE) vulnerability has been identified in Eigent. This vulnerability allows an attacker to execute arbitrary code on the victim's machine or server through a specific interaction (1-click). This issue has been patched in version 0.0.61. | ||||