Path Traversal Vulnerability in ag2ai UserProxyAgent Component
CVE-2026-108543
Key Information:
Badges
What is CVE-2026-108543?
A vulnerability exists in the ag2ai product, specifically within the UserProxyAgent component, affecting versions up to 0.13.4. This issue arises from improper handling of the filename argument in the os.path.join function, allowing for a path traversal attack. Such an exploit enables unauthorized access to system files, as attackers can manipulate the input to traverse directories. This vulnerability has been publicly disclosed, raising concerns for systems that have not yet been patched. Despite early notifications, the vendor has not responded to this serious disclosure.
Affected Version(s)
ag2 0.13.0
ag2 0.13.1
ag2 0.13.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
