CVE-2026-29870: Path traversal enables arbitrary file write in agentic-context-engine
A directory traversal flaw in the agentic-context-engine project (versions up to 0.7.1) lets the checkpoint_dir parameter in OfflineACE.run escape the intended directory because save_to_file in ace/skillbook.py does not normalise or validate paths. Attackers can overwrite arbitrary files accessible to the application process, potentially causing corruption, privilege escalation or code execution.
Disclosed 31 March 2026 · Record updated 13 September 2026
Impact
Arbitrary file writes outside the checkpoint directory, potentially leading to application corruption, privilege escalation or code execution depending on deployment.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-29870
