Description
agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, allowing the agent to access any file on the system without restriction.
Published: 2026-09-30
Score: n/a
EPSS: n/a
KEV: No
Impact: Unrestricted File System Access
Action: Apply Patch
AI Analysis

Impact

The FileBrowser class in agent-zero 1.7–1.10 incorrectly sets the host’s root directory as the workspace without validating input paths, creating a directory traversal hole. This flaw lets an attacker direct the agent to read or write any file on the system, enabling full file‑system compromise, data disclosure, and potential code execution if the agent has elevated privileges.

Affected Systems

Agent-zero versions 1.7, 1.8, 1.9, and 1.10 are affected. The vulnerability resides in python/helpers/file_browser.py and affects systems running those releases, regardless of host operating system, because the code does not enforce a restricted working directory.

Risk and Exploitability

No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, but the impact is substantial. Exploitation requires that an attacker can influence the agent’s configuration or invoke its FileBrowser component, which is typically local to the host running the agent. Once triggered, the attacker can traverse the file system, read sensitive data, or overwrite critical files. The lack of input validation and privilege restrictions make this a high‑risk scenario for any compromised or improperly secured agent deployment.

Generated by OpenCVE AI on September 30, 2026 at 23:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a patched release of agent-zero once it becomes available.
  • Run the agent under the least privilege possible, ideally in a sandboxed or chrooted environment with restricted filesystem access.
  • Modify the FileBrowser implementation to validate and normalize requested paths, ensuring the resolved absolute path remains within a preconfigured workspace directory.

Generated by OpenCVE AI on September 30, 2026 at 23:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Directory Traversal Allows Full File System Access in Agent-Zero
Weaknesses CWE-200
CWE-22

Wed, 30 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, allowing the agent to access any file on the system without restriction.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T20:50:45.094Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51853

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:17:11.400

Modified: 2026-09-30T21:17:11.400

Link: CVE-2026-51853

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T23:15:14Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')