Vulnerability Description
AGiXT is a dynamic AI Agent Automation Platform. Prior to 1.9.2, the safe_join() function in the essential_abilities extension fails to validate that resolved file paths remain within the designated agent workspace. An authenticated attacker can use directory traversal sequences to read, write, or delete arbitrary files on the server hosting the AGiXT instance. This vulnerability is fixed in 1.9.2.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Agixt | Agixt | < 1.9.2 |
Related Weaknesses (CWE)
References
- https://github.com/Josh-XT/AGiXT/commit/2079ea5a88fa671a921bf0b5eba887a5a1b73d5fPatch
- https://github.com/Josh-XT/AGiXT/releases/tag/v1.9.2ProductRelease Notes
- https://github.com/Josh-XT/AGiXT/security/advisories/GHSA-5gfj-64gh-mgmwExploitVendor Advisory
FAQ
What is CVE-2026-39981?
CVE-2026-39981 is a vulnerability with a CVSS score of 8.8 (HIGH). AGiXT is a dynamic AI Agent Automation Platform. Prior to 1.9.2, the safe_join() function in the essential_abilities extension fails to validate that resolved file paths remain within the designated a...
How severe is CVE-2026-39981?
CVE-2026-39981 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-39981?
Check the references section above for vendor advisories and patch information. Affected products include: Agixt Agixt.