Description
A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component code_task_files. Executing a manipulation can lead to path traversal. The attack can be launched remotely. This patch is called 35d97bca0531894da36a85aedb95312da1bd5b7a. It is best practice to apply a patch to resolve this issue.
Published: 2026-08-28
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Path Traversal
Action: Patch
AI Analysis

Impact

A flaw exists in the code_task_files component of houtini-lm up to version 2.13.2 that fails to sanitize file paths. The vulnerability allows an attacker to craft input that leads to path traversal, potentially enabling them to access or manipulate files outside the intended directory. The vulnerability is exploitable remotely, meaning an attacker only needs network access to the service to trigger the flaw.

Affected Systems

Affected vendor and product: houtini-ai, houtini-lm. All releases up to and including version 2.13.2 are impacted. The patch commit 35d97bca0531894da36a85aedb95312da1bd5b7a has been issued to resolve the issue.

Risk and Exploitability

The CVSS score of 5.1 classifies the vulnerability as moderate. The EPSS score is currently unavailable, and it is not listed in CISA’s KEV catalog, indicating no confirmed large‑scale exploitation yet. Nevertheless, the remote attack surface and the potential to reveal or alter sensitive files make the risk material for systems that expose the code_task_files API to untrusted users or the internet. Administrators should treat the vulnerability as a priority for remediation.

Generated by OpenCVE AI on August 28, 2026 at 16:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest release of houtini-lm (v2.13.3 or later) which includes the patch commit 35d97bca0531894da36a85aedb95312da1bd5b7a.
  • Restrict file system permissions so that only the houini‑lm service can access the directories intended for the code_task_files component.
  • If updating immediately is not feasible, limit exposure by disabling the code_task_files API endpoint for untrusted traffic or removing it from production environments.

Generated by OpenCVE AI on August 28, 2026 at 16:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component code_task_files. Executing a manipulation can lead to path traversal. The attack can be launched remotely. This patch is called 35d97bca0531894da36a85aedb95312da1bd5b7a. It is best practice to apply a patch to resolve this issue.
Title houtini-ai houtini-lm code_task_files index.ts path traversal
First Time appeared Houtini-ai
Houtini-ai houtini-lm
Weaknesses CWE-22
CPEs cpe:2.3:a:houtini-ai:houtini-lm:*:*:*:*:*:*:*:*
Vendors & Products Houtini-ai
Houtini-ai houtini-lm
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Houtini-ai Houtini-lm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-28T16:00:34.718Z

Reserved: 2026-08-28T05:25:22.452Z

Link: CVE-2026-82112

cve-icon Vulnrichment

Updated: 2026-08-28T16:00:31.039Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T16:18:31.610

Modified: 2026-08-28T20:20:14.960

Link: CVE-2026-82112

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:32:00Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')