Impact
The vulnerability is a directory traversal flaw in the executeStep file-step implementation that fails to validate the user-supplied step.path before resolving it to an absolute path. As a result, an authenticated user who can create or modify workflow file steps can supply path fragments that escape the intended workspace and read or overwrite sensitive files outside the approved directory. This could expose confidential data or allow an attacker to modify backend‑accessible application files, potentially leading to a broader compromise of the system.
Affected Systems
The affected product is vmDeshpande:ai-agent-automation. Versions prior to v0.9.1 are vulnerable. The issue was fixed in release v0.9.1, which is the current stable baseline. Users running earlier versions should upgrade immediately to remediate the issue.
Risk and Exploitability
The CVSS v3 score of 8.1 classifies the flaw as High severity. However, the EPSS score of under 1% indicates a low likelihood of exploitation at present. The flaw requires authentication and the ability to modify workflow steps, thus the attack surface is restricted to legitimate or compromised users within the application. Because the backend process has file write permissions, an attacker could gain persistence or modify critical files if they have sufficient privileges. The flaw is not listed in CISA’s KEV catalog.
OpenCVE Enrichment