CVE-2026-65702 | vanna-ai vanna up to 2.0.2 conversation_id path traversal

SecurityVulns

A vulnerability, which was classified as critical, was found in vanna-ai vanna up to 2.0.2. The affected element is an unknown function of the component FileSystemConversationStore persistence integration. Executing a manipulation of the argument conversation_id can lead to path traversal. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is tracked as CVE-2026-65702. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More