CVE WATCH / VULNERABILITY DETAIL
CVE-2026-51853
HIGHCVSS 7.5NVD feed
Published 30 September 2026 · tracked since 1 October 2026
Description
agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, allowing the agent to access any file on the system without restriction.
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-97661 HIGH 7.2
- CVE-2026-92244 HIGH 7.2
- CVE-2026-95687 HIGH 8.8
- CVE-2026-96268 MEDIUM 6.4
- CVE-2026-96573 HIGH 7.2
- CVE-2026-96813 HIGH 7.2
- CVE-2026-15983 HIGH 8.1
- CVE-2026-85235 HIGH 7.2
- CVE-2026-89424 MEDIUM 6.4
- CVE-2026-90992 MEDIUM 6.4