Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-51852

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

agent-zero 1.7、1.8、1.9 和 1.10 版本在 文件的 方法中存在目录遍历(Directory Traversal)漏洞。该 方法接受用户可控的文件路径,但未对其进行规范化处理或验证,从而允许攻击者实施路径遍历攻击。

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-51852

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-51852

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-51852

请登录查看更多情报信息。

Other References for CVE-2026-51852 (2)

Same Patch Batch · n/a · 2026-09-30 · 20 CVEs total

CVE-2026-51568 8.1 HIGH CVE-2026-51568
CVE-2026-51570 8.1 HIGH CVE-2026-51570
CVE-2026-103227 6.3 MEDIUM GPAC DASH Client dash_client.c gf_dash_resolve_url buffer overflow
CVE-2026-103118 4.3 MEDIUM GraphicsMagick WPG File wpg.c ExtractPostscript recursion
CVE-2026-51864 CVE-2026-51864
CVE-2026-51856 CVE-2026-51856
CVE-2026-51866 CVE-2026-51866
CVE-2026-51869 CVE-2026-51869
CVE-2026-51862 CVE-2026-51862
CVE-2026-51859 CVE-2026-51859
CVE-2026-51853 CVE-2026-51853
CVE-2026-51857 CVE-2026-51857
CVE-2026-51871 CVE-2026-51871
CVE-2026-51860 CVE-2026-51860
CVE-2026-51872 CVE-2026-51872
CVE-2026-51867 CVE-2026-51867
CVE-2026-51861 CVE-2026-51861
CVE-2026-51858 CVE-2026-51858
CVE-2026-51870 CVE-2026-51870

IV. Related Vulnerabilities

V. Comments for CVE-2026-51852

No comments yet


Leave a comment