CVE-2026-51853
Received
Received - Intake
Directory Traversal Vulnerability in agent-zero
Vulnerability report for CVE-2026-51853, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-30
Last updated on: 2026-09-30
Assigner: MITRE
Description
Description
agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, allowing the agent to access any file on the system without restriction.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| agent-zero | agent-zero | 1.7 |
| agent-zero | agent-zero | 1.8 |
| agent-zero | agent-zero | 1.9 |
| agent-zero | agent-zero | 1.10 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |