CVE-2026-51880: Path Traversal
Published Oct 1, 2026
·Updated
deeptutor 1.4.0 contains a path traversal issue in EditFileTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to write or edit absolute paths outside the intended bot workspace.
Affected Software
1 affected component
deeptutor=1.4.0
Event History
Oct 1, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:17 PM
Description
Frequently Asked Questions
1
Does exploitation require local access to the host?
No. The issue is described as exploitable by a remote caller through the live tutorbot WebSocket interface.
2
Are versions other than 1.4.0 confirmed to be affected?
The available information identifies deeptutor 1.4.0 only. It does not confirm whether earlier or later versions are affected.