Описание
A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function create_workflow of the file python_a2a/agent_flow/server/api.py. The manipulation leads to path traversal. Upgrading to version 0.5.6 is able to address this issue. It is recommended to upgrade the affected component.
Ссылки
- ExploitIssue Tracking
- ExploitIssue Tracking
- Release Notes
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- ExploitIssue Tracking
Уязвимые конфигурации
Конфигурация 1Версия до 0.5.5 (включая)
cpe:2.3:a:themanojdesai:python_a2a:*:*:*:*:*:*:*:*
EPSS
Процентиль: 5%
0.00021
Низкий
5.5 Medium
CVSS3
9.8 Critical
CVSS3
5.2 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 5.5
github
6 месяцев назад
python-a2a has a path traversal in the create_workflow function
EPSS
Процентиль: 5%
0.00021
Низкий
5.5 Medium
CVSS3
9.8 Critical
CVSS3
5.2 Medium
CVSS2
Дефекты
CWE-22