Sceawere
Vulnerability Detail
CVE-2026-78250UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Bytebot Agent Execution Infinite Loop
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- bytebot-ai
- Product
- bytebot
- Attack Type
- Infinite Loop
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in bytebot-ai bytebot 0.0.1. The affected element is an unknown function of the component Agent Execution Workflow. Such manipulation leads to infinite loop. The attack may be performed from remote. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-08-24T14:17:04.223Z",
"pubdate": "2026-08-24T14:17:04.223Z",
"executiveSummary": "A vulnerability has been identified in bytebot-ai bytebot version 0.0.1, specifically residing within the Agent Execution Workflow component.\nThe vulnerability involves an unspecified function that is susceptible to manipulation, resulting in an infinite loop condition during execution.\nThis flaw allows remote threat actors to trigger resource exhaustion or denial of service conditions against affected deployments.\nThe risk is exacerbated by the public availability of an exploit, increasing the likelihood of active exploitation in the wild.\nAffected systems and products are limited to software versions that are no longer supported by the maintainer, meaning official vendor patches or updates will not be provided.\nSuccessful exploitation requires network access to the target system to interact with the exposed Agent Execution Workflow component, enabling remote execution without requiring prior authentication or elevated privileges, depending on the network configuration.",
"technicalDetails": "The vulnerability exists within the Agent Execution Workflow component of bytebot-ai bytebot version 0.0.1, specifically affecting an unknown internal function responsible for processing workflow instructions or execution states.\nThe root cause stems from improper input validation or state management within the affected function, failing to enforce termination conditions, loop invariants, or resource consumption limits.\nWhen a remote attacker interacts with the vulnerable endpoint or supplies maliciously crafted inputs to the Agent Execution Workflow, the execution engine enters an unrecoverable iterative cycle.\nThe attack flow begins with the remote transmission of a trigger or payload to the exposed network service handling the agent workflow.\nUpon receiving the request, the vulnerable function processes the input and initiates a repeating sequence of execution blocks without advancing the state machine or decrementing a counter.\nThis payload behavior consumes critical system resources, primarily CPU cycles and memory allocations, leading to thread starvation and system unresponsiveness.\nThe network exposure of the vulnerability allows unauthenticated remote attackers to initiate requests over standard protocols depending on the application deployment architecture.\nBecause the affected component lacks proper boundary checks, repeated invocations can rapidly exhaust available server resources, resulting in a localized denial of service.\nPost-exploitation impact is primarily characterized by service degradation, application crashes, and potential disruption of dependent automated workflows managed by the bytebot-ai bytebot instance.\nGiven that the product is unsupported by the maintainer, internal defensive controls must be applied at the network or host level to prevent exploitation."
}