PT-2026-64038 · Git+1 · Vanna

·

CVE-2026-65702

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vanna versions prior to 2.0.3
Description A path traversal issue exists in the FileSystemConversationStore persistence integration. Unauthenticated remote attackers can use path traversal sequences in the conversation id parameter sent to unauthenticated chat API endpoints to bypass the base directory. This allows the creation of attacker-controlled JSON files in arbitrary filesystem locations and the unauthorized reading of conversation metadata from outside the intended directory.
Recommendations Update Vanna to version 2.0.3 or later. Restrict the use of the conversation id parameter in chat API endpoints to prevent path traversal attempts.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65702

Affected Products

Vanna