Impact
The FileBrowser class in agent-zero 1.7–1.10 incorrectly sets the host’s root directory as the workspace without validating input paths, creating a directory traversal hole. This flaw lets an attacker direct the agent to read or write any file on the system, enabling full file‑system compromise, data disclosure, and potential code execution if the agent has elevated privileges.
Affected Systems
Agent-zero versions 1.7, 1.8, 1.9, and 1.10 are affected. The vulnerability resides in python/helpers/file_browser.py and affects systems running those releases, regardless of host operating system, because the code does not enforce a restricted working directory.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, but the impact is substantial. Exploitation requires that an attacker can influence the agent’s configuration or invoke its FileBrowser component, which is typically local to the host running the agent. Once triggered, the attacker can traverse the file system, read sensitive data, or overwrite critical files. The lack of input validation and privilege restrictions make this a high‑risk scenario for any compromised or improperly secured agent deployment.
OpenCVE Enrichment