Sceawere
Vulnerability Detail
CVE-2026-108543UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ag2 Path Traversal Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 2h ago
- Vendor
- ag2ai
- Product
- ag2
- Attack Type
- Path Traversal
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in ag2ai ag2 up to 0.13.4. Affected by this issue is the function os.path.join of the component UserProxyAgent. This manipulation of the argument filename causes path traversal. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-11T08:16:33.723Z",
"pubdate": "2026-10-11T08:16:33.723Z",
"executiveSummary": "The ag2ai ag2 library, specifically within the UserProxyAgent component, contains a path traversal vulnerability in versions up to 0.13.4. This vulnerability arises due to the improper handling of user-supplied input when utilizing the os.path.join function for file operations. The flaw allows an unauthenticated, remote attacker to manipulate the filename argument, potentially enabling unauthorized file system access outside of the intended directory.\nThis vulnerability poses a significant security risk, as successful exploitation could lead to unauthorized read or write access to sensitive files on the host system depending on the context of the execution. The vulnerability is exploitable remotely, and since exploit details have been publicly disclosed, the risk of exploitation by malicious actors is increased. The vendor has not responded to initial disclosures, leaving users exposed to potential compromise. Immediate attention is required to implement defensive measures to restrict file path access and prevent directory traversal attempts.",
"technicalDetails": "The root cause of this vulnerability lies in the insecure concatenation of user-provided input with base paths within the UserProxyAgent component of ag2ai ag2. The application utilizes the os.path.join function to construct file paths; however, it fails to sanitize or validate the filename argument for directory traversal sequences (e.g., '../').\nIn a standard implementation, os.path.join is designed to join one or more path components intelligently. However, if an attacker provides a crafted string containing traversal sequences as the filename argument, they can escape the intended directory boundaries defined by the application. Because the application logic does not impose strict constraints or use canonicalization techniques to verify that the final resulting path remains within the designated safe directory, the underlying operating system resolves the path to unintended locations.\nThe attack flow proceeds as follows: 1. An attacker identifies an endpoint or interface within the UserProxyAgent component that accepts a filename or file-related parameter. 2. The attacker crafts a malicious request containing directory traversal sequences, such as '../../../../etc/passwd', injected into the filename field. 3. The application passes this unsanitized input directly into the os.path.join function. 4. The function resolves the path, resulting in an absolute path that points to a restricted file outside the intended working directory. 5. The application performs the requested operation (e.g., reading, writing, or accessing) on the resolved malicious path, granting the attacker unauthorized interaction with the host file system.\nThis vulnerability is classified as a path traversal flaw, enabling remote exploitation without the need for prior authentication or elevated privileges. The impact is determined by the permissions under which the ag2 process is running. If the process executes with high-level privileges, the attacker could theoretically read sensitive configuration files, credentials, or write malicious code to critical system areas, leading to full system compromise or remote code execution. Given that the exploit has been publicly disclosed, the barrier to entry for potential attackers is low, and the lack of a vendor patch necessitates manual remediation efforts to mitigate the risk of exploitation."
}