Void path traversal in AI agent file-reading tools
Void through version 1.3.4 contains a path traversal vulnerability in AI agent file-reading tools that allows network-adjacent attackers to read arbitrary files outside the workspace by injecting instructions into content the agent processes. Attackers can silently exfiltrate sensitive files such as SSH keys or cloud credentials.
Disclosed 23 July 2026 · Record updated 13 September 2026
Impact
Sensitive files including SSH private keys and cloud credentials can be exfiltrated via path traversal in file-reading tools
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-65698
