Path Traversal Vulnerability in AI Agent Automation by vmDeshpande
CVE-2026-54520
8.1HIGH
What is CVE-2026-54520?
AI Agent Automation is susceptible to a path traversal vulnerability due to the incorrect handling of user-controlled input in the executeStep functionality. The affected implementation allows authenticated users to manipulate the step.path value, enabling them to escape the designated workflow directory. This vulnerability could lead to unauthorized access to sensitive files within the application’s environment, such as reading or overwriting files outside the intended workspace. It is crucial for users running versions prior to 0.9.1 to upgrade to the latest release to mitigate this risk.
Affected Version(s)
ai-agent-automation < 0.9.1
