Impact
The reported flaw allows an attacker to manipulate the filename argument passed to the UserProxyAgent component’s os.path.join function. This abuse results in a path traversal condition that can expose files outside the intended directory. The exploit is described as remotely possible, enabling the attacker to read or potentially write arbitrary files depending on the host permissions granted to the application. The vulnerability is present in ag2ai ag2 up to version 0.13.4, and no public patch has yet been issued by the vendor, which may leave systems exposed until an update becomes available.
Affected Systems
ag2ai’s ag2 monolith is affected, specifically the UserProxyAgent part that processes filename inputs. The affected releases are all versions of ag2ai ag2 from the initial launch through 0.13.4 inclusive. No further granular version details appear in the advisory, so any deployment of ag2ai ag2 older than 0.13.5 should be treated as vulnerable.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability carries moderate risk. No EPSS score is listed, and the flaw is not currently in the CISA KEV catalog, implying a lower measurement of immediate exploitation activity. Nonetheless, the description states that the exploit has been publicly disclosed and can be carried out remotely, suggesting that an attacker who can reach the vulnerable service could conduct the attack with minimal preconditions. The absence of a vendor response compounds the risk until a patch is released.
OpenCVE Enrichment