Path Traversal Vulnerability in Evolver AI Engine by GEP
CVE-2026-42075

8.1HIGH

Key Information:

Vendor

Evomap

Status
Vendor
CVE Published:
4 May 2026

What is CVE-2026-42075?

Evolver, a self-evolving AI engine powered by GEP, is susceptible to a path traversal vulnerability in the skill download functionality. This vulnerability, present before version 1.69.3, allows attackers to exploit the '--out=' flag, which does not validate user-provided paths. An attacker can perform directory traversal attacks, leading to the potential overwriting of crucial system files or the creation of files within sensitive directories. This issue was resolved in version 1.69.3, highlighting the importance of keeping software up to date to mitigate such security risks.

Affected Version(s)

evolver < 1.69.3

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.