Directory Traversal and Symlink Vulnerabilities in Activepieces AI Automation Platform
CVE-2026-53535
What is CVE-2026-53535?
Activepieces is an open-source AI workflow automation platform that had a vulnerability in its git-sync feature prior to version 0.82.0. This flaw enabled an attacker controlling a user-configured remote Git repository to exploit symbolic link handling and unsanitized identifiers. By utilizing symlinks within the Git repo, an attacker could redirect writes to arbitrary file paths on the server, potentially leading to unauthorized file overwrites. Users with permissions to push to a git-sync repository could unintentionally trigger scenarios that allow tampering, denial of service, or even remote code execution, thus threatening the integrity and security of the deployment. This issue was addressed in version 0.82.0, making it critical for users to update to the latest version to mitigate the risk.
Affected Version(s)
activepieces < 0.82.0
