Impact
MoAI-ADK version 3.1.2 and earlier contain an improper link resolution vulnerability in the template deployer. The flaw allows a malicious repository to include a symlink that points outside the intended staging directory, causing the deployment process to overwrite any file that the executing process can write. The consequence is unauthorized modification of filesystem data, potentially including configuration files, code, or other sensitive material, leading to integrity compromise.
Affected Systems
The vulnerability affects projects that use the modu‑ai MoAI‑ADK software up to and including version 3.1.2. This includes any environment where the moai init command is run against a repository that may be controlled by an attacker.
Risk and Exploitability
The CVSS vector for this flaw scores 4.8, placing it in the moderate severity range. EPSS data is unavailable, so no current exploitation probability is reported, and the flaw is not listed in CISA's KEV. The likely attack vector is a repository that is inadvertently trusted by the team; an attacker commits a symlinked file such that the deployer’s path resolution follows the link and performs an atomic write. Because the flaw involves filesystem access during deployment, an attacker must have the ability to push code or commit changes to the repository, a situation that many teams consider safe by default. The patching effort and mitigation steps are therefore critical for teams using the affected versions.
OpenCVE Enrichment