CVE-2026-108543
Received Received - Intake

Path Traversal in ag2ai ag2 via UserProxyAgent

Vulnerability report for CVE-2026-108543, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulDB

Description

A vulnerability was determined in ag2ai ag2 up to 0.13.4. Affected by this issue is the function os.path.join of the component UserProxyAgent. This manipulation of the argument filename causes path traversal. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
ag2ai ag2 0.13.0
ag2ai ag2 0.13.1
ag2ai ag2 0.13.2
ag2ai ag2 0.13.3
ag2ai ag2 0.13.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108543 is a two-stage vulnerability in AG2's UserProxyAgent. Attackers exploit a legacy filename header to write files to arbitrary absolute paths outside the intended directory. They then plant a fake /.dockerenv file, tricking the system into running code in the host environment instead of a Docker container. This bypasses isolation controls.

Detection Guidance

To detect this vulnerability, inspect logs for unexpected file creation in root directories like /.dockerenv or absolute path writes. Check for prompt injection attempts in AG2 logs, especially involving UserProxyAgent or AssistantAgent. Monitor for unauthorized Docker container escapes or host system access.

Impact Analysis

This vulnerability allows remote attackers to execute arbitrary code on your host system instead of the intended isolated Docker container. It could lead to unauthorized access, data theft, or further compromise of your host machine and connected systems.

Compliance Impact

This vulnerability likely violates compliance requirements for data isolation and security controls in GDPR and HIPAA. It enables unauthorized host system access, risking data breaches and non-compliance with data protection and security standards.

Mitigation Strategies

Immediately update AG2 to a patched version beyond 0.13.4. Disable absolute path handling in UserProxyAgent and AssistantAgent. Implement strict input validation to reject legacy filename headers. Add multi-factor checks for Docker environment detection instead of relying solely on /.dockerenv.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108543. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart