PT-2026-60558 · Unknown · Activepieces
CVE-2026-53535
·
Published
2026-07-16
·
Updated
2026-07-16
CVSS v4.0
5.9
Medium
| Vector | AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Activepieces versions prior to 0.82.0
Description
The git-sync feature clones a user-configured Git repository into a temporary server directory and writes flow, table, and connection state before pushing back. Two weaknesses allow these writes to escape the intended workspace and land on arbitrary paths on the host filesystem. First, Git symbolic-link handling is not disabled during the clone, allowing an attacker controlling the remote repository to use symlinks to redirect writes. Second, user-supplied identifiers used to build on-disk paths, specifically the repository slug and the
externalId of tables, flows, and connections, are not validated against directory-traversal sequences like ../. In self-hosted Enterprise Edition deployments, a user with WRITE PROJECT RELEASE permission can overwrite files accessible to the Activepieces process user, potentially leading to tampering, denial of service, or remote code execution.Recommendations
Update to version 0.82.0.
Exploit
Fix
Path traversal
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Activepieces