Executive brief
Void, an AI-powered code editor, contains a security flaw in how its AI agent handles file access. An attacker can use 'prompt injection'—tricking the AI with malicious instructions hidden in a file or webpage—to make the agent silently steal sensitive files from the user's computer, such as SSH keys or cloud credentials. Because the AI agent does not ask for permission before reading these files, the theft can occur without the user's knowledge.
Technical details
A path traversal vulnerability (CWE-22) exists in the AI agent tools of the Void editor (up to version 1.3.4). The 'read_file', 'ls_dir', 'get_dir_tree', and 'search_*' tools fail to implement workspace confinement, allowing the use of absolute paths and 'file://' URIs. Furthermore, these specific tools are omitted from the 'approvalTypeOfBuiltinToolName' configuration, causing them to bypass the user approval gate. An attacker can exploit this via indirect prompt injection—placing malicious instructions in a file the agent is asked to process—to force the agent to read sensitive files (e.g., ~/.ssh/id_rsa) and exfiltrate them through subsequent tool calls. The repository was archived in June 2026, and no official patch is currently available.
Affected products
- voideditor Void through 1.3.4
Timeline
- 2026-06-03: other: Repository archived by owner
- 2026-06-12: disclosed: Vulnerability reported to MITRE
- 2026-07-23: advisory: NVD advisory published