Impact
A vulnerability was identified in Tencent AI-Infra-Guard up to versions 4.5.2 and 4.6.2. The startsWith function in dir_actions.py of the File Access component does not correctly validate path prefixes, permitting a local user to craft a path that escapes the intended directory boundary and access arbitrary files. This flaw is a CWE-22 path traversal weakness, enabling local disclosure of sensitive files if the attacker can provide input to the tool.
Affected Systems
The affected product is Tencent AI-Infra-Guard. Versions up to 4.5.2 and 4.6.2 are vulnerable; a patch was incorporated in release 4.6.0 (commit ac0384edc9dbea3b226edefcf50613bd8509134f). The component impacted is the File Access module within skill_scan/tools/dir/dir_actions.py.
Risk and Exploitability
The CVSS score is 2.4, indicating low overall severity. EPSS is not available, so the probability of exploitation is unclear, but the vulnerability is local and requires the attacker to have user-level access to the system running AI-Infra-Guard. An exploit is publicly available, so a host with permissive local access could use the path traversal to read sensitive files. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited presently.
OpenCVE Enrichment