Path Traversal Vulnerability in Activepieces Open Source AI Automation Platform
CVE-2026-48499

9.3CRITICAL

Key Information:

Vendor
CVE Published:
30 July 2026

What is CVE-2026-48499?

Activepieces, an open source AI workflow automation platform, is susceptible to a path traversal vulnerability due to an unsanitized path segment in the Code piece sandbox. This flaw allows an authenticated flow author to access and potentially modify cached flow and code files that belong to other tenants operating on the same worker. Consequently, sensitive embedded data could be exposed, and maliciously altered code might execute on a victim tenant's subsequent flow execution. The issue has been resolved in version 0.84.0.

Affected Version(s)

activepieces < 0.84.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.