Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-65698

Опубликовано: 23 июл. 2026
Источник: redhat
CVSS3: 5.3

Описание

A flaw was found in Void through 1.3.4 in the AI agent file-reading tools (read_file, ls_dir, get_dir_tree, and search_*). Those tools do not confine paths to the open workspace and can accept absolute paths or file:// URIs, including bypassing the approval gate. An attacker who can inject instructions into content the agent processes may read arbitrary host files and exfiltrate sensitive data such as SSH keys or cloud credentials.

Отчет

Void is vulnerable to path traversal in AI agent file tools that lack workspace confinement. A remote attacker who can get malicious instructions into agent-processed content (user interaction, high attack complexity) may read files outside the workspace via absolute paths or file:// URIs and exfiltrate them through later tool calls. Affects Void through 1.3.4.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/vector-rhel9Fix deferred
Red Hat Enterprise Linux 10firefoxFix deferred
Red Hat Enterprise Linux 10gjsFix deferred
Red Hat Enterprise Linux 10rpm-ostreeFix deferred
Red Hat Enterprise Linux 10rustFix deferred
Red Hat Enterprise Linux 10rust-afterburnFix deferred
Red Hat Enterprise Linux 10rust-ssh-key-dirFix deferred
Red Hat Enterprise Linux 10stratisdFix deferred
Red Hat Enterprise Linux 10thunderbirdFix deferred
Red Hat Enterprise Linux 7firefoxFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2506533Void: Void: Sensitive file exfiltration via AI agent path traversal vulnerability

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
9 дней назад

Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injecting instructions into content the agent processes. Attackers can supply absolute paths or file:// URIs through the read_file, ls_dir, get_dir_tree, and search_* tools, which lack workspace confinement and bypass the approval gate, enabling silent exfiltration of sensitive files such as SSH private keys or cloud credentials via subsequent tool calls.

CVSS3: 5.3
github
9 дней назад

Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injecting instructions into content the agent processes. Attackers can supply absolute paths or file:// URIs through the read_file, ls_dir, get_dir_tree, and search_* tools, which lack workspace confinement and bypass the approval gate, enabling silent exfiltration of sensitive files such as SSH private keys or cloud credentials via subsequent tool calls.

5.3 Medium

CVSS3