CVE-2025-55523

An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.
Configurations

Configuration 1 (hide)

cpe:2.3:a:agent-zero:agent-zero:*:*:*:*:*:*:*:*

History

08 Jan 2026, 14:28

Type Values Removed Values Added
References () https://github.com/agent0ai/agent-zero/issues/687 - () https://github.com/agent0ai/agent-zero/issues/687 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/frdel/agent-zero/blob/v0.8.7/python/api/download_work_dir_file.py - () https://github.com/frdel/agent-zero/blob/v0.8.7/python/api/download_work_dir_file.py - Product
References () https://www.cve.org/CVERecord?id=CVE-2025-6166 - () https://www.cve.org/CVERecord?id=CVE-2025-6166 - Not Applicable
First Time Agent-zero agent-zero
Agent-zero
CPE cpe:2.3:a:agent-zero:agent-zero:*:*:*:*:*:*:*:*

22 Aug 2025, 18:08

Type Values Removed Values Added
Summary
  • (es) Un problema en el componente /api/download_work_dir_file.py de Agent-Zero v0.8.* permite a los atacantes ejecutar un directory traversal.

21 Aug 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.5
CWE CWE-22

21 Aug 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-21 18:15

Updated : 2026-01-08 14:28


NVD link : CVE-2025-55523

Mitre link : CVE-2025-55523

CVE.ORG link : CVE-2025-55523


JSON object : View

Products Affected

agent-zero

  • agent-zero
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')