PT-2026-31665 · Agixt · Agixt

Published

2026-04-08

·

Updated

2026-05-13

·

CVE-2026-39981

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AGiXT versions prior to 1.9.2
Description AGiXT is a dynamic AI Agent Automation Platform. The safe join() function in the essential abilities extension does not properly validate file paths, allowing authenticated attackers to use directory traversal sequences to read, write, or delete arbitrary files on the server. The vulnerability resides in the interaction between the /api/agent/MyAgent/command API endpoint, the execute command function, and the safe join() function within the essential abilities extension. The vulnerable parameter is filename within the command args of the read file command. This can lead to credential theft, persistent code execution, or denial of service.
Recommendations Update to AGiXT version 1.9.2 or later.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-39981
GHSA-5GFJ-64GH-MGMW

Affected Products

Agixt