Path Traversal Vulnerability in AI Agent Automation by vmDeshpande
CVE-2026-54520

8.1HIGH

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-54520?

AI Agent Automation is susceptible to a path traversal vulnerability due to the incorrect handling of user-controlled input in the executeStep functionality. The affected implementation allows authenticated users to manipulate the step.path value, enabling them to escape the designated workflow directory. This vulnerability could lead to unauthorized access to sensitive files within the application’s environment, such as reading or overwriting files outside the intended workspace. It is crucial for users running versions prior to 0.9.1 to upgrade to the latest release to mitigate this risk.

Affected Version(s)

ai-agent-automation < 0.9.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.