CVE-2025-8667 Overview
CVE-2025-8667 is an OS command injection vulnerability [CWE-77] in SkyworkAI DeepResearchAgent, affecting commits up to 08eb7f8eb9505d0094d75bb97ff7dacc3fa3bbf2. The flaw resides in the from_code, from_dict, and from_mcp functions within src/tools/tools.py. An authenticated remote attacker can manipulate input to these functions to execute arbitrary operating system commands on the host running the agent. The project uses continuous delivery with rolling releases, so no fixed version is published. The vendor was contacted prior to disclosure but did not respond, and a public proof-of-concept has been released.
Critical Impact
Remote command injection in an AI research agent framework, enabling arbitrary OS command execution with the privileges of the agent process.
Affected Products
- SkyworkAI DeepResearchAgent (rolling release)
- Builds up to and including commit 08eb7f8eb9505d0094d75bb97ff7dacc3fa3bbf2
- src/tools/tools.py tool-loading functions (from_code, from_dict, from_mcp)
Discovery Timeline
- 2025-08-06 - CVE-2025-8667 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8667
Vulnerability Analysis
DeepResearchAgent is an AI agent framework that loads tool definitions dynamically from code strings, dictionaries, and Model Context Protocol (MCP) descriptors. The from_code, from_dict, and from_mcp constructors in src/tools/tools.py instantiate tools from attacker-influenced input without validating or sandboxing the resulting execution. As a result, strings passed into these functions can reach an OS command interpreter and execute arbitrary commands.
The vulnerability is classified under CWE-77: Improper Neutralization of Special Elements used in a Command. The current EPSS probability is 1.754% (percentile 77.17), indicating moderate predicted exploitation interest. A proof-of-concept is publicly available in the vul-36 repository.
Root Cause
The root cause is the absence of input sanitization in the tool-loading pathway. Code, dictionary, and MCP tool descriptors are trusted as safe inputs and passed to execution primitives that invoke the system shell. Because the agent framework is designed to accept dynamically defined tools, user- or network-supplied payloads reach command execution without an intermediate validation layer.
Attack Vector
Exploitation requires network access and low-privileged interaction with the agent, consistent with the CVSS 4.0 vector published for this CVE. An attacker submits a crafted tool definition through any interface that reaches from_code, from_dict, or from_mcp and includes shell metacharacters or command sequences in the payload. When the agent instantiates the tool, the embedded commands execute in the context of the agent process.
See the public proof-of-concept and the VulDB entry 319026 for payload structure and reproduction steps.
Detection Methods for CVE-2025-8667
Indicators of Compromise
- Unexpected child processes (for example sh, bash, cmd.exe, powershell.exe) spawned by the Python interpreter hosting DeepResearchAgent.
- Outbound network connections from the agent host to unknown IP addresses shortly after tool-registration requests.
- Entries in agent logs showing tool definitions containing shell metacharacters such as ;, |, &&, or backticks.
Detection Strategies
- Instrument the Python runtime to log all invocations of from_code, from_dict, and from_mcp with the full payload for offline review.
- Deploy process-ancestry monitoring to alert when the agent process spawns shells or system utilities such as curl, wget, nc, or whoami.
- Correlate inbound API requests that register or modify tools with subsequent process creation events on the agent host.
Monitoring Recommendations
- Forward agent application logs and host process telemetry to a centralized analytics platform for cross-source correlation.
- Baseline the normal set of child processes created by the agent and alert on deviations.
- Monitor outbound DNS and HTTP traffic from the agent host for anomalous destinations that could indicate second-stage payload retrieval.
How to Mitigate CVE-2025-8667
Immediate Actions Required
- Restrict network exposure of the DeepResearchAgent interface so only trusted, authenticated clients can submit tool definitions.
- Audit all tool-registration endpoints and disable any that are not strictly required for operations.
- Run the agent under a dedicated, least-privileged service account with no interactive shell and limited filesystem access.
Patch Information
No vendor patch is available. The project uses continuous delivery with rolling releases, and the vendor did not respond to the disclosure attempt. Operators should track the upstream repository for future commits addressing from_code, from_dict, and from_mcp and review changes before deployment. See VulDB analysis 319026 for ongoing tracking.
Workarounds
- Place the agent behind an authenticating reverse proxy that filters tool-definition payloads for shell metacharacters.
- Execute the agent inside a container or sandbox with no shell binaries available on PATH and with egress network policies enforced.
- Apply a local wrapper around from_code, from_dict, and from_mcp to reject payloads containing command separators or process-invocation primitives.
- Disable MCP tool loading entirely in deployments that do not require it.
# Example container hardening for the DeepResearchAgent service
docker run --rm \
--read-only \
--cap-drop=ALL \
--security-opt no-new-privileges \
--user 10001:10001 \
--network agent-restricted \
deepresearchagent:latest
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.