Description
deeptutor 1.4.0 contains a path traversal issue in EditFileTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to write or edit absolute paths outside the intended bot workspace.
Published: 2026-10-01
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Update
AI Analysis

Impact

DeepTutor 1.4.0 contains a path traversal flaw in the EditFileTool.execute method. An attacker who can reach the live tutorbot WebSocket interface can direct the tool layer to write or edit files using any absolute path on the host system. Consequently, the attacker can modify configuration files, overwrite critical data, or place malicious code that may be executed by the process running the bot service, leading to full remote code execution. The vulnerability therefore exposes both confidentiality and integrity, with the potential for a total loss of control over the affected host.

Affected Systems

The flaw affects DeepTutor version 1.4.0. No specific vendor is listed, but the product is the DeepTutor WebSocket tutoring platform, which must be running that version to be vulnerable.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the security agency’s KEV catalog, so the exact prevalence of exploitation is unknown. However, the flaw permits remote exploitation via a standard WebSocket connection, which is a common remote interface. The lack of restrictions on the EditFileTool implies that any authenticated or unauthenticated user who can reach the WebSocket endpoint can trigger the file write operation. Given the potential to overwrite arbitrary files, the risk is high, especially if the DeepTutor service runs with elevated privileges.

Generated by OpenCVE AI on October 1, 2026 at 22:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade DeepTutor to a patched version once it becomes available
  • Restrict or disable WebSocket access to the EditFileTool layer, limiting usage to trusted users or internal services
  • Deploy filesystem controls (e.g., chroot, container isolation, or read‑only workspaces) and enforce strict path validation to prevent writes outside the intended workspace

Generated by OpenCVE AI on October 1, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
Title DeepTutor 1.4.0 Path Traversal Allows Unauthorized Absolute File Write via WebSocket
Weaknesses CWE-20

Thu, 01 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description deeptutor 1.4.0 contains a path traversal issue in EditFileTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to write or edit absolute paths outside the intended bot workspace.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-01T21:33:43.101Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51880

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T22:17:02.763

Modified: 2026-10-01T22:17:02.763

Link: CVE-2026-51880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:30:14Z

Weaknesses
  • CWE-20

    Improper Input Validation