CVE-2026-51852: Path Traversal
Published Sep 30, 2026
·Updated
agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/filebrowser.py:FileBrowser.savefileb64. The savefileb64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks.
Affected Software
1 affected component
agent-zero=1.7, =1.8, =1.9, =1.10
Event History
Sep 30, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:17 PM
Description