Path Traversal Vulnerability in Evolver AI Engine by GEP
CVE-2026-42075
8.1HIGH
What is CVE-2026-42075?
Evolver, a self-evolving AI engine powered by GEP, is susceptible to a path traversal vulnerability in the skill download functionality. This vulnerability, present before version 1.69.3, allows attackers to exploit the '--out=' flag, which does not validate user-provided paths. An attacker can perform directory traversal attacks, leading to the potential overwriting of crucial system files or the creation of files within sensitive directories. This issue was resolved in version 1.69.3, highlighting the importance of keeping software up to date to mitigate such security risks.
Affected Version(s)
evolver < 1.69.3
