PT-2026-29270 · Unknown · Agentic-Context-Engine

Lilmingwa13

·

Publicado

2026-03-31

·

Atualizado

2026-03-31

·

CVE-2026-29870

CVSS v3.1

7.6

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions agentic-context-engine versions up to 0.7.1
Description A directory traversal issue exists in the agentic-context-engine project. The checkpoint dir parameter within OfflineACE.run is susceptible to manipulation. The save to file method, located in ace/skillbook.py, does not properly sanitize or validate file system paths, enabling attackers to use traversal sequences to bypass the intended checkpoint directory. Successful exploitation could allow overwriting arbitrary files accessible to the application process, potentially resulting in application corruption, privilege escalation, or code execution. The vulnerable parameter is checkpoint dir.
Recommendations Versions prior to 0.7.1 should be updated.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-29870

Produtos afetados

Agentic-Context-Engine