Executive brief
A security vulnerability exists in Griptape, a framework used for building AI applications. The flaw is located in the file management component, which could allow an attacker to access or modify files outside of the intended directory. This could lead to the exposure of sensitive system data or the unauthorized modification of application files.
Technical details
A path traversal vulnerability (CWE-22) exists in the FileManagerTool component of griptape-ai griptape version 0.19.4. The issue resides in several functions, including load_files_from_disk, list_files_from_disk, save_content_to_file, and save_memory_artifacts_to_disk. By providing specially crafted file paths, a remote attacker with low privileges can bypass directory restrictions to read or write files on the underlying host system. As of the advisory date, the vendor has not responded to the disclosure, and a public exploit is reportedly available.
Affected products
- griptape-ai griptape 0.19.4
Timeline
- 2026-04-05: disclosed: Public disclosure of the vulnerability and exploit
- 2026-04-05: advisory: NVD and VulDB publication date