What happened
Coordinated disclosure batch: agent-zero lacks path normalization (full-filesystem access + traversal), and DeepTutor/Devika execute model output with no approval boundary — all permissive-by-design agent harnesses with no isolation.
Why it matters
A prompt-injected prompt in any of these agents becomes host file read/write or arbitrary code execution; representative of the permissive local-agent class where the sandbox IS the whole filesystem.
Attack vector
agent-zero's FileBrowser lets the agent read/write any system file and save_file_b64 accepts traversal paths (CVE-2026-51852/51853); DeepTutor's ExecTool.execute and Devika's Runner.execute directly run LLM-generated Python/shell content (CVE-2026-51870/51871).
Affected systems
agent-zero 1.7–1.10 (FileBrowser.save_file_b64 / __init__), DeepTutor v1.4.0 (ExecTool.execute), Devika v1.0 (Runner.execute)
Mitigation
Update agent-zero, DeepTutor, and Devika to patched versions; restrict workspace roots and add approval boundaries.