Executive brief
A vulnerability in the nexent AI agent platform allows unauthorized individuals to delete critical data. By sending a specifically crafted request to the system's search interface, an attacker can permanently remove documents and storage files without needing a password. This can result in significant data loss and the disruption of services relying on the platform.
Technical details
The nexent backend service (v1.7.5.2) is vulnerable to unauthorized arbitrary file deletion via its ElasticSearch service interface. The 'DELETE /{index_name}/documents' endpoint fails to implement proper authentication and authorization controls. Furthermore, the service does not validate the user-supplied 'path_or_url' parameter. An unauthenticated remote attacker can exploit this by sending crafted HTTP DELETE requests to remove arbitrary documents from ElasticSearch indices and their associated files within the MinIO storage system. This vulnerability is classified under CWE-552 (Files or Directories Accessible to External Parties).
Affected products
- ModelEngine-Group nexent 1.7.5.2
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory