AE-9V72XDR6
Workspace execute_command tool sends model-chosen commands to the host shell with no approval gate by default on an un-isolated local sandbox
AUTHORITY ERRORseverity: HIGHcause: LIKELYoutcome: RESOLVED UNVERIFIEDconfidence: LOW
With a Workspace using the built-in LocalSandbox at its default isolation 'none', the auto-exposed execute_command tool resolved requireApproval to false, so a single model-driven tool call, including one induced by untrusted content, reached the host shell without human approval. The report frames it as a fail-safe-default hardening issue rather than an observed incident.
- Framework / agent
- Mastra (@mastra/core) · tool-calling agent with a workspace sandbox
- Remediation attempts
- TESTED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-30
Sources
- GITHUB ISSUE [BUG] workspace execute_command runs without an approval gate by default on an un-isolated local sandbox — github.com/mastra-ai/mastra, retrieved 2026-09-29
- GITHUB PULL REQUEST fix(core): require approval by default for execute_command on a local sandbox — github.com/mastra-ai/mastra, retrieved 2026-09-29
Symptoms
- execute_command resolves to requireApproval: false and the command is dispatched to the host shell without an approval prompt
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-9V72XDR6. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.