Junglewise Threat Intelligence

CVE-2026-31216: ModelEngine-Group nexent arbitrary file deletion in file management API

CVE-2026-31216 · Severity: critical · CVSS 9.1 · Published 2026-05-12

Executive brief

Nexent, a platform for building AI agents, contains a critical security flaw in its file management system. An unauthenticated attacker can remotely delete any file stored within the system's backend storage. This could result in permanent data loss and cause the service to stop functioning correctly.

Technical details

The vulnerability exists in the nexent backend service (v1.7.5.2) due to a lack of security controls on the 'DELETE /storage/{object_name:path}' API endpoint. This endpoint fails to implement authentication, authorization, or proper input validation. A remote, unauthenticated attacker can exploit this by sending a crafted HTTP DELETE request with a user-controlled 'object_name' path parameter. This allows for the unauthorized deletion of arbitrary objects/files within the underlying MinIO storage system. The flaw is categorized under CWE-552 (Files or Directories Accessible to External Parties).

Affected products

  • ModelEngine-Group nexent 1.7.5.2

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Initial publication of CVE-2026-31216

References

Related threats