Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rp38-pj7h-r8q2

Опубликовано: 17 июн. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 5.5

Описание

python-a2a has a path traversal in the create_workflow function

A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function create_workflow of the file python_a2a/agent_flow/server/api.py. The manipulation leads to path traversal. Upgrading to version 0.5.6 is able to address this issue. It is recommended to upgrade the affected component.

Пакеты

Наименование

python-a2a

pip
Затронутые версииВерсия исправления

< 0.5.6

0.5.6

EPSS

Процентиль: 8%
0.00031
Низкий

5.1 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.5
nvd
8 месяцев назад

A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function create_workflow of the file python_a2a/agent_flow/server/api.py. The manipulation leads to path traversal. Upgrading to version 0.5.6 is able to address this issue. It is recommended to upgrade the affected component.

EPSS

Процентиль: 8%
0.00031
Низкий

5.1 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-22