Vulnerability  ·  2026-07-31

Activepieces AI Workflow Platform - Cross-Tenant Path Traversal in Code Sandbox Exposes Other Tenants' Flow Data

VulnerabilityHigh impactGlobalCVE-2026-48499
In shared multi-tenant AI workflow automation deployments, this breaks the tenant isolation boundary that enterprise customers rely on, allowing one customer's low-privilege flow author to read or tamper with another customer's AI automation logic and embedded credentials.
An unsanitized path segment in the Code piece sandbox allows an authenticated flow author to reach read-write cached flow and code files belonging to other tenants sharing the same worker, exposing embedded secrets/data and allowing modification of other tenants' workflow code.
Activepieces prior to 0.84.0
Upgrade to Activepieces 0.84.0 or later.
GitHub commit - Activepieces fixNVD - CVE-2026-48499
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →