Path Traversal Vulnerability in Activepieces Open Source AI Automation Platform
CVE-2026-48499
9.3CRITICAL
What is CVE-2026-48499?
Activepieces, an open source AI workflow automation platform, is susceptible to a path traversal vulnerability due to an unsanitized path segment in the Code piece sandbox. This flaw allows an authenticated flow author to access and potentially modify cached flow and code files that belong to other tenants operating on the same worker. Consequently, sensitive embedded data could be exposed, and maliciously altered code might execute on a victim tenant's subsequent flow execution. The issue has been resolved in version 0.84.0.
Affected Version(s)
activepieces < 0.84.0
