CVE-2026-51852
- EPSS 0.24%
- Veröffentlicht 30.09.2026 00:00:00
- Zuletzt bearbeitet 07.10.2026 16:17:48
agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traver...
CVE-2026-51853
- EPSS 0.65%
- Veröffentlicht 30.09.2026 00:00:00
- Zuletzt bearbeitet 01.10.2026 19:17:20
agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, allowing the agent to access any file on ...
CVE-2026-30624
- EPSS 0.41%
- Veröffentlicht 15.04.2026 00:00:00
- Zuletzt bearbeitet 20.04.2026 20:17:28
Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows users to define MCP servers using a JSON configuration containing arbitrary command and args values. These value...
CVE-2025-55523
- EPSS 1.05%
- Veröffentlicht 21.08.2025 00:00:00
- Zuletzt bearbeitet 08.01.2026 14:28:50
An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.
CVE-2025-55524
- EPSS 0.35%
- Veröffentlicht 21.08.2025 00:00:00
- Zuletzt bearbeitet 08.01.2026 14:22:58
Insecure permissions in Agent-Zero v0.8.* allow attackers to arbitrarily reset the system via unspecified vectors.
CVE-2025-6166
- EPSS 0.54%
- Veröffentlicht 17.06.2025 06:00:19
- Zuletzt bearbeitet 08.01.2026 14:46:06
A vulnerability was found in frdel Agent-Zero up to 0.8.4. It has been rated as problematic. This issue affects the function image_get of the file /python/api/image_get.py. The manipulation of the argument path leads to path traversal. Upgrading to v...
CVE-2025-3547
- EPSS 0.44%
- Veröffentlicht 14.04.2025 02:00:09
- Zuletzt bearbeitet 08.01.2026 14:46:52
A vulnerability classified as critical was found in frdel Agent-Zero 0.8.1.2. This vulnerability affects unknown code of the file /get_work_dir_files. The manipulation of the argument path leads to path traversal. The attack can be initiated remotely...