Sceawere
Vulnerability Detail
CVE-2026-108751UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MoAI-ADK Improper Link Resolution Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.4
- Creation Date
- 4h ago
- Vendor
- modu-ai
- Product
- moai-adk
- Attack Type
- Improper Link Resolution Before File Access ('Link Following')
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
MoAI-ADK through 3.1.2 contains an improper link resolution vulnerability in the moai init template deployer that allows malicious repositories to overwrite files outside the project via a symlinked .moai-tmp staging path. Attackers can commit a symlink such as .claude/settings.json.moai-tmp so atomicWriteFile truncates and overwrites victim-writable files with MoAI template content.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.4",
"pubDate": "2026-10-11T13:17:19.957Z",
"pubdate": "2026-10-11T13:17:19.957Z",
"executiveSummary": "The MoAI-ADK library, specifically the moai init template deployer, is susceptible to an improper link resolution vulnerability affecting versions through 3.1.2. This flaw enables attackers to bypass filesystem boundaries by leveraging symlinks within the .moai-tmp staging path.\nBy crafting a malicious repository that includes symlinks designed to point to arbitrary file locations, an attacker can coerce the atomicWriteFile function into truncating and overwriting sensitive files on the host system with the contents of a template.\nThe vulnerability represents a significant security risk, as it permits arbitrary file overwrite capabilities under the privileges of the user executing the deployment process. Successful exploitation requires the victim to initialize or deploy a template from a malicious source. This impacts local development environments and automated deployment pipelines, potentially leading to unauthorized modification of system configuration files, credentials, or application source code.\nThe core issue stems from insufficient validation of symbolic links during the file deployment process, failing to ensure that file operations remain contained within the intended directory scope. Remediation requires implementing robust path validation or canonicalization checks to prevent traversal attacks.",
"technicalDetails": "The vulnerability resides within the moai init template deployer component of MoAI-ADK (versions <= 3.1.2). The root cause is a failure to perform adequate input sanitization and link resolution checks when handling files during the template deployment sequence.\nThe attack vector involves the use of symbolic links within the staging directory used by the deployer, specifically targeting the .moai-tmp path. An attacker prepares a malicious repository containing a symlink structure that maps a filename to a sensitive target path outside of the application's root directory (e.g., ../../../home/user/.ssh/authorized_keys or .claude/settings.json).\nWhen the MoAI-ADK deployer initiates the template deployment, it interacts with the file system using the atomicWriteFile function. Because the deployer does not resolve the final destination of symlinked paths before performing the write operation, it follows the symlink to the attacker-specified target on the host filesystem.\nStep-by-step exploitation flow: 1) The attacker commits a symlink to their repository with a name ending in .moai-tmp that points to a victim's writable file. 2) The victim executes a template initialization or deployment process using the compromised repository. 3) The moai init deployer attempts to write template data to the staged path. 4) The atomicWriteFile function encounters the symlink, resolves the target path, and proceeds to truncate and overwrite the destination file with template content.\nThis behavior results in a local arbitrary file overwrite. Because atomicWriteFile performs a truncation operation as part of its write-to-temporary-file-then-rename cycle, the existing content of the target file is destroyed and replaced by the malicious template data. The impact is limited to the privileges of the user running the MoAI-ADK deployment. However, in environments where the deployment utility is run by highly privileged users or inside automated CI/CD runners, the post-exploitation impact includes persistent configuration modification, privilege escalation through SSH key injection, or code execution by overwriting sensitive application configuration files."
}