Executive brief
A security vulnerability exists in the agentic-context-engine, a tool used for managing context in AI agents. An attacker can exploit this flaw to write or overwrite files anywhere on the server's hard drive. This could lead to the system being taken over, important data being corrupted, or the application being completely disabled.
Technical details
A path traversal vulnerability (CWE-22) exists in the agentic-context-engine project through version 0.7.1. The root cause is located in the save_to_file method within ace/skillbook.py, which fails to normalize or validate filesystem paths provided via the checkpoint_dir parameter in OfflineACE.run. A remote attacker with low privileges can provide malicious path sequences (e.g., ../) to escape the restricted directory and write arbitrary files with the permissions of the application process. This capability can be leveraged to overwrite sensitive system files or configuration files to achieve code execution or escalate privileges.
Affected products
- lilmingwa13 agentic-context-engine up to 0.7.1
Timeline
- 2026-03-31: disclosed
- 2026-03-31: advisory