CVE Details
Basic Information
| Title | frdel Agent-Zero image_get.py image_get path traversal |
|---|---|
| Type | cve |
| Published | 2025-06-17T06:00:19.953Z |
| Last Seen |
Product Information
| Vendor | frdel |
|---|---|
| Product | Agent-Zero |
| Version | 0.8.0 |
CVSS Information
| Base Score | 5.1 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A path traversal vulnerability in the `image_get` function of frdel Agent-Zero allows attackers to access arbitrary files on the system by manipulating the `path` argument. This issue affects versions up to 0.8.4 and is fixed in version 0.8.4.1. |
|---|---|
| AI Severity | Medium |
| Vendor | frdel |
| Product | Agent-Zero |
| Affected Version | up to 0.8.4 |
Affected Products
- frdel Agent-Zero 0.8.0
- frdel Agent-Zero 0.8.1
- frdel Agent-Zero 0.8.2
- frdel Agent-Zero 0.8.3
- frdel Agent-Zero 0.8.4
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-22 |
| Bulletin Family |
References
- https://vuldb.com/?id.312641
- https://vuldb.com/?ctiid.312641
- https://vuldb.com/?submit.593611
- https://github.com/frdel/agent-zero/issues/383
- https://github.com/frdel/agent-zero/issues/383#issuecomment-2893239897
- https://github.com/frdel/agent-zero/commit/5db74202d632306a883ccce7339c5bdba0d16c5a
- https://github.com/frdel/agent-zero/releases/tag/v0.8.4.1
Description
A vulnerability was found in frdel Agent-Zero up to 0.8.4. It has been rated as problematic. This issue affects the function image_get of the file /python/api/image_get.py. The manipulation of the argument path leads to path traversal. Upgrading to version 0.8.4.1 is able to address this issue. The identifier of the patch is 5db74202d632306a883ccce7339c5bdba0d16c5a. It is recommended to upgrade the affected component.