PT-2026-99923 · Tencent · Ai-Infra-Guard

·

CVE-2026-101080

·

Published

2026-09-28

·

Updated

2026-10-01

CVSS v3.1

4.8

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tencent AI-Infra-Guard versions prior to 4.6.0
Description A path traversal issue exists within the File Access component, specifically affecting the startsWith() function in the skill scan/tools/dir/dir actions.py file. This flaw allows a local attacker to manipulate file paths to access unauthorized directories.
Recommendations Upgrade to version 4.6.0. As a temporary mitigation, restrict local access to the File Access component to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101080

Affected Products

Ai-Infra-Guard