Description
MoAI-ADK through 3.1.2 contains an improper link resolution vulnerability in the moai init template deployer that allows malicious repositories to overwrite files outside the project via a symlinked .moai-tmp staging path. Attackers can commit a symlink such as .claude/settings.json.moai-tmp so atomicWriteFile truncates and overwrites victim-writable files with MoAI template content.
Published: 2026-10-11
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized File Modification
Action: Apply Patch
AI Analysis

Impact

MoAI-ADK version 3.1.2 and earlier contain an improper link resolution vulnerability in the template deployer. The flaw allows a malicious repository to include a symlink that points outside the intended staging directory, causing the deployment process to overwrite any file that the executing process can write. The consequence is unauthorized modification of filesystem data, potentially including configuration files, code, or other sensitive material, leading to integrity compromise.

Affected Systems

The vulnerability affects projects that use the modu‑ai MoAI‑ADK software up to and including version 3.1.2. This includes any environment where the moai init command is run against a repository that may be controlled by an attacker.

Risk and Exploitability

The CVSS vector for this flaw scores 4.8, placing it in the moderate severity range. EPSS data is unavailable, so no current exploitation probability is reported, and the flaw is not listed in CISA's KEV. The likely attack vector is a repository that is inadvertently trusted by the team; an attacker commits a symlinked file such that the deployer’s path resolution follows the link and performs an atomic write. Because the flaw involves filesystem access during deployment, an attacker must have the ability to push code or commit changes to the repository, a situation that many teams consider safe by default. The patching effort and mitigation steps are therefore critical for teams using the affected versions.

Generated by OpenCVE AI on October 11, 2026 at 13:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MoAI‑ADK to version 3.1.3 or later.
  • Restrict repository content to disallow symlinked files in the template directory.
  • Run the deployment process as a non‑privileged user and enforce strict path checks or use a temporary staging area that rejects external links.

Generated by OpenCVE AI on October 11, 2026 at 13:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description MoAI-ADK through 3.1.2 contains an improper link resolution vulnerability in the moai init template deployer that allows malicious repositories to overwrite files outside the project via a symlinked .moai-tmp staging path. Attackers can commit a symlink such as .claude/settings.json.moai-tmp so atomicWriteFile truncates and overwrites victim-writable files with MoAI template content.
Title MoAI-ADK through 3.1.2 Symlink Following via moai init Template Deployer
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:51.354Z

Reserved: 2026-10-11T01:54:14.881Z

Link: CVE-2026-108751

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:19.957

Modified: 2026-10-11T13:17:19.957

Link: CVE-2026-108751

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:00:18Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')