PT-2026-103602 · Unknown · Agent-Zero

·

CVE-2026-51852

·

Published

2026-09-30

·

Updated

2026-09-30

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions agent-zero versions 1.7 through 1.10
Description A directory traversal issue exists in the save file b64() function within the python/helpers/file browser.py file. The function accepts user-controlled file paths without proper normalization or validation, which allows an attacker to access or overwrite files outside the intended directory.
Recommendations Update agent-zero versions 1.7 through 1.10 to a version where the save file b64() function is patched. As a temporary mitigation, restrict access to the save file b64() function until a fix is applied.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-51852

Affected Products

Agent-Zero