NONE · 0

CVE-2026-48499

Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an authenticated flow author reach read-write cached flow...

Vulnerability Description

Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an authenticated flow author reach read-write cached flow and code files belonging to other tenants on the same worker, exposing embedded data and allowing modified code to execute on a victim tenant's next flow run. This issue is fixed in version 0.84.0.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-48499?

CVE-2026-48499 is a documented vulnerability. Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an authenticated flow author reach read-write cached flow...

How severe is CVE-2026-48499?

CVSS scoring is not yet available for CVE-2026-48499. Check NVD for updates.

Is there a patch for CVE-2026-48499?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.