Description
AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value through path.resolve with process.cwd() and then uses the resulting path for read or write operations without checking that it remains in an approved workflow directory. An authenticated user who can create or modify workflow file steps can supply traversal segments to escape the intended workspace and read sensitive files or write and overwrite files accessible to the backend process, including application-adjacent files when process permissions allow. This issue is fixed in version 0.9.1.
Published: 2026-09-17
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Read/Write
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a directory traversal flaw in the executeStep file-step implementation that fails to validate the user-supplied step.path before resolving it to an absolute path. As a result, an authenticated user who can create or modify workflow file steps can supply path fragments that escape the intended workspace and read or overwrite sensitive files outside the approved directory. This could expose confidential data or allow an attacker to modify backend‑accessible application files, potentially leading to a broader compromise of the system.

Affected Systems

The affected product is vmDeshpande:ai-agent-automation. Versions prior to v0.9.1 are vulnerable. The issue was fixed in release v0.9.1, which is the current stable baseline. Users running earlier versions should upgrade immediately to remediate the issue.

Risk and Exploitability

The CVSS v3 score of 8.1 classifies the flaw as High severity. However, the EPSS score of under 1% indicates a low likelihood of exploitation at present. The flaw requires authentication and the ability to modify workflow steps, thus the attack surface is restricted to legitimate or compromised users within the application. Because the backend process has file write permissions, an attacker could gain persistence or modify critical files if they have sufficient privileges. The flaw is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on September 19, 2026 at 01:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the AI Agent Automation installation to version v0.9.1 or later to apply the vendor fix.
  • If an update cannot be performed immediately, restrict the backend process’s filesystem permissions to read‑only or remove write access to directories that contain sensitive files, and, if possible, configure the operating system to deny write access to any paths outside the designated workflow directory.
  • Audit and review all workflow file steps in your environment to ensure that only authorized users can create or modify them, and enable additional logging or monitoring of file access events to detect any unauthorized attempts.

Generated by OpenCVE AI on September 19, 2026 at 01:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Vmdeshpande
Vmdeshpande ai-agent-automation
Vendors & Products Vmdeshpande
Vmdeshpande ai-agent-automation
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value through path.resolve with process.cwd() and then uses the resulting path for read or write operations without checking that it remains in an approved workflow directory. An authenticated user who can create or modify workflow file steps can supply traversal segments to escape the intended workspace and read sensitive files or write and overwrite files accessible to the backend process, including application-adjacent files when process permissions allow. This issue is fixed in version 0.9.1.
Title AI Agent Automation: Workflow file step path traversal allows read and write outside the expected directory
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Vmdeshpande Ai-agent-automation
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T18:32:38.051Z

Reserved: 2026-06-15T18:40:01.651Z

Link: CVE-2026-54520

cve-icon Vulnrichment

Updated: 2026-09-18T17:24:16.594Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:01.090

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-54520

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:00:13Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')