Impact
A flaw in TinyAGI 0.0.20 allows manipulation of input that causes the collectFiles function in the Message API Endpoint’s response.ts to include arbitrary files. The vulnerability is based on the ability to reference files outside the intended directory, a weakness classified as CWE‑73. An attacker can trigger the flaw remotely by sending a crafted request to the vulnerable endpoint, and a publicly available exploit demonstrates that the inclusion can be exploited to deliver malicious files, potentially enabling code execution or disclosure of confidential data.
Affected Systems
Only TinyAGI version 0.0.20 is listed as affected and no subsequent releases or patches have been reported. The vendor is TinyAGI, and the project has not yet issued a fix or responded to the reported issue.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, so the statistical likelihood of exploitation is uncertain. However, a publicly available exploit exists, and the vulnerability can be triggered without local access, keeping the risk level high until a patch or effective mitigation is applied.
OpenCVE Enrichment