Agent-Zero v0.8.0 - 0.9.4 contains a path traversal caused by improper validation in /api/download_work_dir_file.py, letting attackers access unauthorized files, exploit requires crafted request.
id: CVE-2025-55523
info:
name: Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download
author: 0x_Ak
...