PT-2026-64029 · Void · Void
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Void versions prior to 1.3.5
Description
A path traversal issue exists in the AI agent file-reading tools. Network-adjacent attackers can read arbitrary host files outside the open workspace by injecting instructions into content processed by the agent. This is possible because the
read file, ls dir, get dir tree, and search * tools lack workspace confinement and bypass the approval gate. Attackers can use absolute paths or file:// URIs to silently exfiltrate sensitive data, such as SSH private keys or cloud credentials, through subsequent tool calls.Recommendations
Update Void to version 1.3.5 or later.
As a temporary mitigation, restrict the use of the
read file, ls dir, get dir tree, and search * tools.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Void