PT-2026-95149 · Unknown · Ai-Agent-Automation
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
AI Agent Automation versions prior to 0.9.1
Description
An authenticated user capable of creating or modifying workflow file steps can exploit a path traversal flaw in the
executeStep file-step implementation located in backend/src/agents/executor.js. The system passes the user-controlled step.path variable through path.resolve with process.cwd() and performs read or write operations without verifying if the resulting path remains within an approved workflow directory. This allows an attacker to use traversal segments to escape the intended workspace, enabling the reading of sensitive files or the writing and overwriting of files accessible to the backend process, including application-adjacent files depending on process permissions.Recommendations
Update to version 0.9.1.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ai-Agent-Automation