CVE-2026-101080
Received Received - Intake

Path Traversal in Tencent AI-Infra-Guard

Vulnerability report for CVE-2026-101080, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skill_scan/tools/dir/dir_actions.py of the component File Access. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version 4.6.0 is able to mitigate this issue. The identifier of the patch is ac0384edc9dbea3b226edefcf50613bd8509134f. You should upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
tencent ai-infra-guard to 4.5.2 (inc)
tencent ai-infra-guard to 4.6.2 (inc)
tencent ai-infra-guard 4.6.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal issue in Tencent AI-Infra-Guard up to versions 4.5.2/4.6.2. It affects the startsWith function in skill_scan/tools/dir/dir_actions.py, allowing manipulation of file paths to access restricted directories. The flaw occurs because the code uses str.startswith() to check if a path is within an allowed folder, which can be bypassed using techniques like symlinks or relative paths. An attacker could exploit this to access files outside the intended sandbox.

Detection Guidance

To detect this vulnerability, check if your system is running Tencent AI-Infra-Guard versions up to 4.5.2 or 4.6.2. Inspect the files skill_scan/tools/dir/dir_actions.py, skill_scan/tools/file/write_file.py, skill_scan/tools/grep/grep_actions.py, and mcp-scan/mcp_scan/tools/file/write_file.py for the use of startsWith() for path validation. If these patterns exist, the system is vulnerable.

Impact Analysis

This vulnerability could allow an attacker with local access to read or write files outside the intended directory, potentially accessing sensitive data like secrets or configuration files. In CI environments, it might expose build secrets or other critical information. The exploit is publicly available, increasing the risk of misuse.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized file access through path traversal. If exploited, it might enable attackers to read or write sensitive files outside intended directories, such as accessing confidential data or secrets in CI environments. This could lead to data breaches or unauthorized disclosure of personal or health information, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information.

Mitigation Strategies

Upgrade Tencent AI-Infra-Guard to version 4.6.0 or later. This version includes the patch that replaces startsWith() with os.path.commonpath() for proper path containment checks. The patch commit is ac0384edc9dbea3b226edefcf50613bd8509134f.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101080. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart