Directory Traversal and Symlink Vulnerabilities in Activepieces AI Automation Platform
CVE-2026-53535

5.9MEDIUM

Key Information:

Vendor
CVE Published:
16 July 2026

What is CVE-2026-53535?

Activepieces is an open-source AI workflow automation platform that had a vulnerability in its git-sync feature prior to version 0.82.0. This flaw enabled an attacker controlling a user-configured remote Git repository to exploit symbolic link handling and unsanitized identifiers. By utilizing symlinks within the Git repo, an attacker could redirect writes to arbitrary file paths on the server, potentially leading to unauthorized file overwrites. Users with permissions to push to a git-sync repository could unintentionally trigger scenarios that allow tampering, denial of service, or even remote code execution, thus threatening the integrity and security of the deployment. This issue was addressed in version 0.82.0, making it critical for users to update to the latest version to mitigate the risk.

Affected Version(s)

activepieces < 0.82.0

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.