PT-2026-29270 · Unknown · Agentic-Context-Engine
Lilmingwa13
·
Publicado
2026-03-31
·
Atualizado
2026-03-31
·
CVE-2026-29870
CVSS v3.1
7.6
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
agentic-context-engine versions up to 0.7.1
Description
A directory traversal issue exists in the agentic-context-engine project. The
checkpoint dir parameter within OfflineACE.run is susceptible to manipulation. The save to file method, located in ace/skillbook.py, does not properly sanitize or validate file system paths, enabling attackers to use traversal sequences to bypass the intended checkpoint directory. Successful exploitation could allow overwriting arbitrary files accessible to the application process, potentially resulting in application corruption, privilege escalation, or code execution. The vulnerable parameter is checkpoint dir.Recommendations
Versions prior to 0.7.1 should be updated.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Agentic-Context-Engine