CVE-2026-30624

8.6

Agent Zero · Agent Zero

Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature due to improper validation of user supplied JSON input.

Executive summary

Agent Zero 0.9.8 is affected by a critical remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands via malicious MCP server configurations.

Vulnerability

The application fails to perform sufficient validation on command and argument values within the External MCP Servers JSON configuration. This flaw allows an unauthenticated attacker to inject and execute arbitrary operating system commands with the privileges of the Agent Zero process.

Business impact

The ability for an unauthenticated remote attacker to execute arbitrary code poses a severe threat to the confidentiality, integrity, and availability of the host system. With a CVSS score of 8.6, this vulnerability represents a high risk that could lead to full system compromise, data exfiltration, or the deployment of persistent threats within the internal network.

Remediation

Immediate Action: Restrict access to the External MCP Servers configuration interface and monitor vendor communications for the release of a security patch addressing this command injection flaw.

Proactive Monitoring: Review system and application logs for suspicious command execution patterns or unauthorized modifications to configuration files involving MCP server definitions.

Compensating Controls: Implement strict network segmentation and egress filtering to prevent the Agent Zero process from initiating unauthorized outbound connections or reaching sensitive internal resources if compromised.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for remote code execution without requiring authentication, this vulnerability must be treated as a high priority. Organizations should immediately audit their Agent Zero deployments to ensure the External MCP Servers feature is not exposed to untrusted networks and prepare to apply security updates as soon as they are made available by the vendor.

More Agent Zero CVEs

Sources