PT-2026-60558 · Unknown · Activepieces

CVE-2026-53535

·

Published

2026-07-16

·

Updated

2026-07-16

CVSS v4.0

5.9

Medium

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Activepieces versions prior to 0.82.0
Description The git-sync feature clones a user-configured Git repository into a temporary server directory and writes flow, table, and connection state before pushing back. Two weaknesses allow these writes to escape the intended workspace and land on arbitrary paths on the host filesystem. First, Git symbolic-link handling is not disabled during the clone, allowing an attacker controlling the remote repository to use symlinks to redirect writes. Second, user-supplied identifiers used to build on-disk paths, specifically the repository slug and the externalId of tables, flows, and connections, are not validated against directory-traversal sequences like ../. In self-hosted Enterprise Edition deployments, a user with WRITE PROJECT RELEASE permission can overwrite files accessible to the Activepieces process user, potentially leading to tampering, denial of service, or remote code execution.
Recommendations Update to version 0.82.0.

Exploit

Fix

Path traversal

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53535
GHSA-QQCR-RG2X-97MM

Affected Products

Activepieces