Impact
This vulnerability exists in the FileBrowser.save_file_b64 method of agent‑zero, which writes Base64‑decoded data to disk using a filename supplied by the caller. The code accepts the path verbatim, with no normalization or validation, making it possible for an attacker to send a path containing directory traversal sequences. The result is that the application can write arbitrary files to any location on the filesystem that the process can access, potentially overwriting configuration files, application binaries, or system files.
Affected Systems
All publicly released agent‑zero versions 1.7, 1.8, 1.9, and 1.10 contain the vulnerable routine. These versions are used in deployments where the agent runs as a daemon and can receive untrusted input over the network or from third‑party plugins. The vulnerability is confined to the python/helpers/file_browser.py module that implements the file‑saving logic.
Risk and Exploitability
No evidence of wild exploitation exists and the issue is not listed in the CISA KEV catalog. However, the lack of path sanitization provides a straightforward attack surface. An adversary who can send a crafted path such as ../../../../etc/passwd can force the agent to create or overwrite files outside the intended directory. If the agent process runs with elevated privileges or can write to system‑critical locations, the attacker could install malicious binaries or alter configuration files, leading to remote code execution or data exfiltration. In environments where the agent accepts unsolicited input from untrusted networks, the risk remains high.
OpenCVE Enrichment