Описание
A flaw was found in Void through 1.3.4 in the AI agent file-reading tools (read_file, ls_dir, get_dir_tree, and search_*). Those tools do not confine paths to the open workspace and can accept absolute paths or file:// URIs, including bypassing the approval gate. An attacker who can inject instructions into content the agent processes may read arbitrary host files and exfiltrate sensitive data such as SSH keys or cloud credentials.
Отчет
Void is vulnerable to path traversal in AI agent file tools that lack workspace confinement. A remote attacker who can get malicious instructions into agent-processed content (user interaction, high attack complexity) may read files outside the workspace via absolute paths or file:// URIs and exfiltrate them through later tool calls. Affects Void through 1.3.4.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/vector-rhel9 | Fix deferred | ||
| Red Hat Enterprise Linux 10 | firefox | Fix deferred | ||
| Red Hat Enterprise Linux 10 | gjs | Fix deferred | ||
| Red Hat Enterprise Linux 10 | rpm-ostree | Fix deferred | ||
| Red Hat Enterprise Linux 10 | rust | Fix deferred | ||
| Red Hat Enterprise Linux 10 | rust-afterburn | Fix deferred | ||
| Red Hat Enterprise Linux 10 | rust-ssh-key-dir | Fix deferred | ||
| Red Hat Enterprise Linux 10 | stratisd | Fix deferred | ||
| Red Hat Enterprise Linux 10 | thunderbird | Fix deferred | ||
| Red Hat Enterprise Linux 7 | firefox | Fix deferred |
Показывать по
Дополнительная информация
Статус:
5.3 Medium
CVSS3
Связанные уязвимости
Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injecting instructions into content the agent processes. Attackers can supply absolute paths or file:// URIs through the read_file, ls_dir, get_dir_tree, and search_* tools, which lack workspace confinement and bypass the approval gate, enabling silent exfiltration of sensitive files such as SSH private keys or cloud credentials via subsequent tool calls.
Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injecting instructions into content the agent processes. Attackers can supply absolute paths or file:// URIs through the read_file, ls_dir, get_dir_tree, and search_* tools, which lack workspace confinement and bypass the approval gate, enabling silent exfiltration of sensitive files such as SSH private keys or cloud credentials via subsequent tool calls.
5.3 Medium
CVSS3