Executive brief
EverOS, a memory runtime for AI agents, contains a vulnerability that allows unauthorized users to write or overwrite files on the server. By sending specially crafted requests to the system's memory ingestion endpoint, an attacker can bypass directory restrictions to place files in sensitive locations. This could lead to data corruption, service disruption, or unauthorized modification of system files.
Technical details
A path traversal vulnerability exists in the POST /api/v1/memory/add endpoint of EverOS prior to version 1.0.1. The 'sender_id' field is used as an 'owner_id' and joined into a filesystem path without proper validation for path-traversal sequences like '../'. An unauthenticated remote attacker can exploit this by providing a malicious 'sender_id' to write or overwrite .md files at arbitrary locations writable by the server process. The vulnerability is mitigated in version 1.0.1 by implementing a character whitelist for 'sender_id' and adding a defense-in-depth check in the MarkdownWriter component to ensure all writes remain within the configured memory root.
Affected products
- EverMind-AI EverOS < 1.0.1
Timeline
- 2026-06-16: patched: Fixes committed and version 1.0.1 released.
- 2026-07-10: disclosed: CVE-2026-58499 published.