CVE-2026-54520 | vmDeshpande ai-agent-automation up to 0.9.0 File Step executor.js executeStep step.path path traversal
A vulnerability was found in vmDeshpande ai-agent-automation up to 0.9.0 and classified as problematic. The affected element is the function executeStep of the file backend/src/agents/executor.js of the component File Step. The manipulation of the argument step.path results in path traversal.
This vulnerability is reported as CVE-2026-54520. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More