PT-2026-31665 · Agixt · Agixt

CVE-2026-39981

·

Published

2026-04-08

·

Updated

2026-05-13

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AGiXT versions prior to 1.9.2
Description AGiXT is a dynamic AI Agent Automation Platform. The safe join() function in the essential abilities extension does not properly validate file paths, allowing authenticated attackers to use directory traversal sequences to read, write, or delete arbitrary files on the server. The vulnerability resides in the interaction between the /api/agent/MyAgent/command API endpoint, the execute command function, and the safe join() function within the essential abilities extension. The vulnerable parameter is filename within the command args of the read file command. This can lead to credential theft, persistent code execution, or denial of service.
Recommendations Update to AGiXT version 1.9.2 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39981
GHSA-5GFJ-64GH-MGMW
PYSEC-2026-2093

Affected Products

Agixt