themanojdesai python-a2a api.py create_workflow path traversal

CVE Details

Basic Information

Title themanojdesai python-a2a api.py create_workflow path traversal
Type cve
Published 2025-06-17T06:31:05.717Z
Last Seen

Product Information

Vendor themanojdesai
Product python-a2a
Version 0.5.0

CVSS Information

Base Score 5.1 (MEDIUM)
Attack Vector CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A path traversal vulnerability in the `create_workflow` function of `python_a2a/agent_flow/server/api.py` allows attackers to access files outside the intended directory, potentially leading to unauthorized data access or system compromise. Upgrading to version 0.5.6 fixes this issue.
AI Severity Medium
Vendor themanojdesai
Product python-a2a
Affected Version 0.5.0, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5

Affected Products

  • themanojdesai python-a2a 0.5.0
  • themanojdesai python-a2a 0.5.1
  • themanojdesai python-a2a 0.5.2
  • themanojdesai python-a2a 0.5.3
  • themanojdesai python-a2a 0.5.4
  • themanojdesai python-a2a 0.5.5

Additional Information

CVE List
CWE List CWE-22
Bulletin Family

Description

A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function create_workflow of the file python_a2a/agent_flow/server/api.py. The manipulation leads to path traversal. Upgrading to version 0.5.6 is able to address this issue. It is recommended to upgrade the affected component.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.