Junglewise Threat Intelligence

CVE-2026-85688: TEN Framework arbitrary file read and write in TMAN Designer

CVE-2026-85688 · Severity: critical · CVSS 9.8 · Published 2026-09-04

Executive brief

TEN Framework is an open-source platform for building conversational AI agents. The TMAN Designer component, used to design and configure AI workflows, lacks authentication controls on file-handling API endpoints. An unauthenticated attacker can read arbitrary files from the server or write malicious content to system directories, potentially executing code through SSH keys, scheduled tasks, or executable graph files.

Technical details

The vulnerability is an authentication bypass combined with arbitrary file read/write in the TMAN Designer's file-content API endpoints (/api/designer/v1/file-content). The vulnerable Rust code directly accepts user-supplied file paths without validation or authentication checks, allowing attackers to submit POST and PUT requests to read any readable file or write to any writable location on the system. An attacker can exploit this to inject SSH public keys, modify cron job files, or write malicious executable graphs, achieving remote code execution. The vulnerability affects TEN Framework version 0.11.71 and likely earlier versions.

Affected products

  • TEN TEN Framework 0.11.71 and likely earlier

Timeline

  • 2026-09-04: disclosed

References