CVE-2026-51853
EUVD-2026-9042530.09.2026, 21:17
agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, allowing the agent to access any file on the system without restriction.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.