Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

redhat логотип

CVE-2026-65698

9 дней назад

A flaw was found in Void through 1.3.4 in the AI agent file-reading tools (read_file, ls_dir, get_dir_tree, and search_*). Those tools do not confine paths to the open workspace and can accept absolute paths or file:// URIs, including bypassing the approval gate. An attacker who can inject instructions into content the agent processes may read arbitrary host files and exfiltrate sensitive data such as SSH keys or cloud credentials.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-65698

9 дней назад

Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injecting instructions into content the agent processes. Attackers can supply absolute paths or file:// URIs through the read_file, ls_dir, get_dir_tree, and search_* tools, which lack workspace confinement and bypass the approval gate, enabling silent exfiltration of sensitive files such as SSH private keys or cloud credentials via subsequent tool calls.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-739h-jx7m-fc7g

9 дней назад

Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injecting instructions into content the agent processes. Attackers can supply absolute paths or file:// URIs through the read_file, ls_dir, get_dir_tree, and search_* tools, which lack workspace confinement and bypass the approval gate, enabling silent exfiltration of sensitive files such as SSH private keys or cloud credentials via subsequent tool calls.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-65698

A flaw was found in Void through 1.3.4 in the AI agent file-reading tools (read_file, ls_dir, get_dir_tree, and search_*). Those tools do not confine paths to the open workspace and can accept absolute paths or file:// URIs, including bypassing the approval gate. An attacker who can inject instructions into content the agent processes may read arbitrary host files and exfiltrate sensitive data such as SSH keys or cloud credentials.

CVSS3: 5.3
0%
Низкий
9 дней назад
nvd логотип
CVE-2026-65698

Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injecting instructions into content the agent processes. Attackers can supply absolute paths or file:// URIs through the read_file, ls_dir, get_dir_tree, and search_* tools, which lack workspace confinement and bypass the approval gate, enabling silent exfiltration of sensitive files such as SSH private keys or cloud credentials via subsequent tool calls.

CVSS3: 5.3
0%
Низкий
9 дней назад
github логотип
GHSA-739h-jx7m-fc7g

Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injecting instructions into content the agent processes. Attackers can supply absolute paths or file:// URIs through the read_file, ls_dir, get_dir_tree, and search_* tools, which lack workspace confinement and bypass the approval gate, enabling silent exfiltration of sensitive files such as SSH private keys or cloud credentials via subsequent tool calls.

CVSS3: 5.3
0%
Низкий
9 дней назад

Уязвимостей на страницу