Vulnerability  ·  2026-10-01

agent-zero / DeepTutor / Devika agent-file & code-execution cluster (directory traversal, shell exec, code injection)

VulnerabilityMedium impactGlobalCVE-2026-51852
Coordinated disclosure batch: agent-zero lacks path normalization (full-filesystem access + traversal), and DeepTutor/Devika execute model output with no approval boundary — all permissive-by-design agent harnesses with no isolation.
A prompt-injected prompt in any of these agents becomes host file read/write or arbitrary code execution; representative of the permissive local-agent class where the sandbox IS the whole filesystem.
agent-zero's FileBrowser lets the agent read/write any system file and save_file_b64 accepts traversal paths (CVE-2026-51852/51853); DeepTutor's ExecTool.execute and Devika's Runner.execute directly run LLM-generated Python/shell content (CVE-2026-51870/51871).
agent-zero 1.7–1.10 (FileBrowser.save_file_b64 / __init__), DeepTutor v1.4.0 (ExecTool.execute), Devika v1.0 (Runner.execute)
Update agent-zero, DeepTutor, and Devika to patched versions; restrict workspace roots and add approval boundaries.
NVD CVE-2026-51852NVD CVE-2026-51870Ro1ME disclosure gists
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →