Description
agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks.
Published: 2026-09-30
Score: n/a
EPSS: n/a
KEV: No
Impact: Arbitrary File Write
Action: Validate Paths
AI Analysis

Impact

This vulnerability exists in the FileBrowser.save_file_b64 method of agent‑zero, which writes Base64‑decoded data to disk using a filename supplied by the caller. The code accepts the path verbatim, with no normalization or validation, making it possible for an attacker to send a path containing directory traversal sequences. The result is that the application can write arbitrary files to any location on the filesystem that the process can access, potentially overwriting configuration files, application binaries, or system files.

Affected Systems

All publicly released agent‑zero versions 1.7, 1.8, 1.9, and 1.10 contain the vulnerable routine. These versions are used in deployments where the agent runs as a daemon and can receive untrusted input over the network or from third‑party plugins. The vulnerability is confined to the python/helpers/file_browser.py module that implements the file‑saving logic.

Risk and Exploitability

No evidence of wild exploitation exists and the issue is not listed in the CISA KEV catalog. However, the lack of path sanitization provides a straightforward attack surface. An adversary who can send a crafted path such as ../../../../etc/passwd can force the agent to create or overwrite files outside the intended directory. If the agent process runs with elevated privileges or can write to system‑critical locations, the attacker could install malicious binaries or alter configuration files, leading to remote code execution or data exfiltration. In environments where the agent accepts unsolicited input from untrusted networks, the risk remains high.

Generated by OpenCVE AI on September 30, 2026 at 23:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check for newer releases of agent‑zero that include a patch to the save_file_b64 routine and upgrade if available.
  • Implement input validation in the file_browser.save_file_b64 method to reject paths containing traversal components, absolute paths, or symbolic links, and normalize the path before writing.
  • Configure the agent to restrict all write operations to a designated safe directory and set strict file system permissions so that even if a traversal attack succeeds, the process cannot modify critical system or application files.

Generated by OpenCVE AI on September 30, 2026 at 23:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Title Directory Traversal in agent‑zero FileBrowser.save_file_b64 Allows Arbitrary File Write

Wed, 30 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T20:49:56.181Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51852

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:17:11.273

Modified: 2026-09-30T21:17:11.273

Link: CVE-2026-51852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T00:00:12Z

Weaknesses

No weakness.