Description
A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skill_scan/tools/dir/dir_actions.py of the component File Access. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version 4.6.0 is able to mitigate this issue. The identifier of the patch is ac0384edc9dbea3b226edefcf50613bd8509134f. You should upgrade the affected component.
Published: 2026-09-28
Score: 2.4 Low
EPSS: n/a
KEV: No
Impact: Local Path Traversal
Action: Apply Patch
AI Analysis

Impact

A vulnerability was identified in Tencent AI-Infra-Guard up to versions 4.5.2 and 4.6.2. The startsWith function in dir_actions.py of the File Access component does not correctly validate path prefixes, permitting a local user to craft a path that escapes the intended directory boundary and access arbitrary files. This flaw is a CWE-22 path traversal weakness, enabling local disclosure of sensitive files if the attacker can provide input to the tool.

Affected Systems

The affected product is Tencent AI-Infra-Guard. Versions up to 4.5.2 and 4.6.2 are vulnerable; a patch was incorporated in release 4.6.0 (commit ac0384edc9dbea3b226edefcf50613bd8509134f). The component impacted is the File Access module within skill_scan/tools/dir/dir_actions.py.

Risk and Exploitability

The CVSS score is 2.4, indicating low overall severity. EPSS is not available, so the probability of exploitation is unclear, but the vulnerability is local and requires the attacker to have user-level access to the system running AI-Infra-Guard. An exploit is publicly available, so a host with permissive local access could use the path traversal to read sensitive files. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited presently.

Generated by OpenCVE AI on September 28, 2026 at 17:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to a patched version of Tencent AI-Infra-Guard, at least 4.6.0, to eliminate the path traversal flaw.
  • If an update cannot be applied immediately, run the File Access component in a restricted environment and enforce the least privilege principle for the process and its file system permissions.
  • Sanitize and validate any file path inputs before they reach the startsWith function, using canonicalization to reject or normalize paths containing directory traversal sequences.
  • Monitor logs for attempted traversal patterns and configure strict path restrictions in the application settings.

Generated by OpenCVE AI on September 28, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skill_scan/tools/dir/dir_actions.py of the component File Access. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version 4.6.0 is able to mitigate this issue. The identifier of the patch is ac0384edc9dbea3b226edefcf50613bd8509134f. You should upgrade the affected component.
Title Tencent AI-Infra-Guard File Access dir_actions.py startsWith path traversal
First Time appeared Tencent
Tencent ai-infra-guard
Weaknesses CWE-22
CPEs cpe:2.3:a:tencent:ai-infra-guard:*:*:*:*:*:*:*:*
Vendors & Products Tencent
Tencent ai-infra-guard
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 4.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Tencent Ai-infra-guard
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T17:36:43.700Z

Reserved: 2026-09-27T18:14:50.850Z

Link: CVE-2026-101080

cve-icon Vulnrichment

Updated: 2026-09-28T17:36:36.790Z

cve-icon NVD

Status : Received

Published: 2026-09-28T16:17:12.820

Modified: 2026-09-28T18:17:16.200

Link: CVE-2026-101080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T18:30:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')