Arbitrary File Read Vulnerability in Mage AI by Mage
CVE-2026-81030

7.1HIGH

Key Information:

Vendor

Mage-ai

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-81030?

Mage AI's browser-items API allows users to supply unvalidated paths, enabling a scenario where unauthorized users can read any file accessible to the server process. This occurs because the functionality bypasses necessary containment checks for file access, potentially exposing sensitive data. Even users with limited permissions, such as the Viewer role, can exploit this flaw, which undermines the expected security boundaries imposed by user roles. Callers with the Editor role possess even greater risk due to their ability to execute code, making it imperative to secure configurations and update to patched versions to mitigate potential exposures.

Affected Version(s)

mage-ai 0 <= 0.9.79

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.