PT-2026-31665 · Agixt · Agixt
Published
2026-04-08
·
Updated
2026-05-13
·
CVE-2026-39981
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AGiXT versions prior to 1.9.2
Description
AGiXT is a dynamic AI Agent Automation Platform. The
safe join() function in the essential abilities extension does not properly validate file paths, allowing authenticated attackers to use directory traversal sequences to read, write, or delete arbitrary files on the server. The vulnerability resides in the interaction between the /api/agent/MyAgent/command API endpoint, the execute command function, and the safe join() function within the essential abilities extension. The vulnerable parameter is filename within the command args of the read file command. This can lead to credential theft, persistent code execution, or denial of service.Recommendations
Update to AGiXT version 1.9.2 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Agixt