CVE-2026-51906
Received Received - Intake

Path Traversal in TaskingAI DALL-E 3 Image Tool

Vulnerability report for CVE-2026-51906, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: MITRE

Description

In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write downloaded images to arbitrary locations on the server filesystem by manipulating the project_id parameter.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
taskingai taskingai 0.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in TaskingAI v0.3.0's DALL-E 3 image generation tool. The save_url_image function in plugin/app/service/image_storage.py allows attackers to write downloaded images to arbitrary locations on the server filesystem by manipulating the project_id parameter. The function constructs file paths by directly concatenating user-controlled input without validation.

Detection Guidance

To detect this vulnerability, inspect network traffic for POST requests to /v1/execute with the X-Project-Id header containing path traversal sequences like ../../../. Check server logs for unexpected file writes outside the intended storage directory. Use commands like grep to search for suspicious project_id values in logs or network captures.

Impact Analysis

Attackers could overwrite critical system files, plant malicious files, or execute arbitrary code on the server. This could lead to complete system compromise, data theft, or denial of service. The vulnerability is accessible via the POST /v1/execute endpoint using a crafted X-Project-Id header with path traversal sequences like ../../../.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. It enables attackers to write files to arbitrary locations, potentially exposing or modifying regulated data without authorization.

Mitigation Strategies

Immediately update TaskingAI to a patched version if available. If not, restrict access to the POST /v1/execute endpoint and sanitize the project_id parameter by validating and normalizing paths. Ensure the project_id is confined to the intended storage directory using path containment checks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-51906. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart