Executive brief
Agnai is an open-source conversational AI platform. A path traversal vulnerability in its image upload feature allows authenticated attackers to write image files to arbitrary locations on the server, potentially overwriting critical system files or enabling website defacement. This affects self-hosted instances that are publicly accessible and do not use S3-compatible storage.
Technical details
This is a path traversal vulnerability (CWE-35, CWE-22) in the image upload handler. An attacker can inject path traversal sequences (e.g., encoded `../` segments) into the character ID parameter of a POST request to `/api/character`, which is then unsanitized and interpolated into the filename used by the `entityUpload()` function. The vulnerable code concatenates the attacker-controlled ID directly into the filename without path normalization, allowing traversal outside the intended upload directory. Exploitation requires authentication (low privilege) and network access to a public-facing Agnai instance; S3-backed deployments are unaffected. The vulnerability was fixed in version 1.0.330.
Affected products
- Agnai Agnai < 1.0.330
Timeline
- 2024-09-26: disclosed
- 2024-09-26: patched: Fixed in version 1.0.330