Arbitrary File Read Vulnerability in Mage AI by Mage
CVE-2026-81030
7.1HIGH
What is CVE-2026-81030?
Mage AI's browser-items API allows users to supply unvalidated paths, enabling a scenario where unauthorized users can read any file accessible to the server process. This occurs because the functionality bypasses necessary containment checks for file access, potentially exposing sensitive data. Even users with limited permissions, such as the Viewer role, can exploit this flaw, which undermines the expected security boundaries imposed by user roles. Callers with the Editor role possess even greater risk due to their ability to execute code, making it imperative to secure configurations and update to patched versions to mitigate potential exposures.
Affected Version(s)
mage-ai 0 <= 0.9.79
