Themanojdesai · Python-A2A · CVE-2025-6167
**Name of the Vulnerable Software and Affected Versions**
themanojdesai python-a2a versions up to 0.5.5
**Description**
A critical vulnerability has been found in themanojdesai python-a2a, affecting the `create workflow` function of the file python a2a/agent flow/server/api.py. The manipulation leads to path traversal.
**Recommendations**
To address this issue, upgrade to version 0.5.6. As a temporary workaround, consider restricting access to the `create workflow` function until the upgrade is applied.