Description

AGiXT is a dynamic AI Agent Automation Platform. Prior to 1.9.2, the safe_join() function in the essential_abilities extension fails to validate that resolved file paths remain within the designated agent workspace. An authenticated attacker can use directory traversal sequences to read, write, or delete arbitrary files on the server hosting the AGiXT instance. This vulnerability is fixed in 1.9.2.

INFO

Published Date :

2026-04-09T17:01:27.069Z

Last Modified :

2026-04-09T17:01:27.069Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-39981 vulnerability.

Vendors Products
Josh-xt
  • Agixt

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact