Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Void path traversal in AI agent file-reading tools

Void through version 1.3.4 contains a path traversal vulnerability in AI agent file-reading tools that allows network-adjacent attackers to read arbitrary files outside the workspace by injecting instructions into content the agent processes. Attackers can silently exfiltrate sensitive files such as SSH keys or cloud credentials.

Disclosed 23 July 2026 · Record updated 13 September 2026

Impact

Sensitive files including SSH private keys and cloud credentials can be exfiltrated via path traversal in file-reading tools

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-65698