CVE-2026-101080: Tencent AI-Infra-Guard File Access dir_actions.py startsWith path traversal
A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skillscan/tools/dir/diractions.py of the component File Access. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version 4.6.0 is able to mitigate this issue. The identifier of the patch is ac0384edc9dbea3b226edefcf50613bd8509134f. You should upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tencent AI-Infra-Guard File Accessto a version that resolves this vulnerability.Fixed in 4.6.0Patch ac0384edc9dbea3b226edefcf50613bd8509134f
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires local access, low privileges, and user interaction. It is therefore most relevant on systems where a local user can interact with the affected File Access functionality.
What versions should be remediated?
Tencent AI-Infra-Guard versions up to 4.5.2 and 4.6.2 are identified as affected. Upgrade the affected component to version 4.6.0; the referenced patch identifier is ac0384edc9dbea3b226edefcf50613bd8509134f.
Is public exploit material available?
Yes. A public exploit is available and may be used, which increases the urgency of upgrading affected installations.