Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

AGiXT path traversal in essential_abilities allows arbitrary file access (CVE-2026-39981)

In AGiXT versions prior to 1.9.2, the safe_join() function in the essential_abilities extension did not verify that resolved paths stayed inside the agent workspace, letting an authenticated attacker use directory traversal to read, write or delete arbitrary files on the host. The issue is fixed in release 1.9.2.

Disclosed 9 April 2026 · Record updated 13 September 2026

Impact

Authenticated attackers could read, write or delete arbitrary files on the server hosting the AGiXT instance, escaping the designated agent workspace.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-39981