Junglewise Threat Intelligence

CVE-2026-54520: AI Agent Automation path traversal in file-step executor

CVE-2026-54520 · Severity: high · CVSS 8.1 · Published 2026-09-17

Executive brief

AI Agent Automation is a workflow automation platform that allows users to create and execute workflows with various step types, including file operations. Prior to version 0.9.1, an authenticated user who can create or modify workflows could exploit a path traversal vulnerability in file-step operations to read sensitive files or overwrite any file accessible to the backend process, potentially compromising the entire system or adjacent applications.

Technical details

The vulnerability is a path traversal flaw in the executeStep file-step implementation (backend/src/agents/executor.js). The vulnerable code passes user-controlled step.path through path.resolve() with process.cwd() without validating that the resulting path remains within the approved workflow directory. An authenticated attacker can supply directory traversal sequences (e.g., ../) to escape the intended workspace and perform arbitrary file read/write operations with the privileges of the backend process. The fix in version 0.9.1 introduces path validation and containment checks via a resolveWorkflowFilePath() function to ensure paths are relative and do not escape the workflow directory.

Affected products

  • vmDeshpande AI Agent Automation prior to 0.9.1

Timeline

  • 2026-06-05: patched: Version 0.9.1 released with path traversal fix
  • 2026-09-17: disclosed: CVE-2026-54520 published

References

Related threats