Impact
The vulnerability is a path traversal flaw in Void 1.3.4’s AI agent file‑reading tools that permits attackers to read files outside the intended workspace. By injecting absolute file paths or file:// URIs into the read_file, ls_dir, get_dir_tree, or search_* tools, an attacker can bypass the approval gate and silently exfiltrate sensitive data such as SSH private keys or cloud credentials. The flaw directly compromises confidentiality by allowing unrestricted access to system files that should not be visible to the AI agent.
Affected Systems
Open editor "void", version 1.3.4. No other versions or products are listed as affected.
Risk and Exploitability
With a CVSS score of 6 the vulnerability is considered moderate. The EPSS score of less than 1% indicates that exploitation is expected to be rare, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑adjacent attacker able to send crafted instructions to the AI agent; the attack requires no special privileges beyond the agent’s existing file‑reading capabilities and therefore poses a local network‑level threat.
OpenCVE Enrichment