Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-54520 — CVE-2026-54520 / GHSA-cm8g-8jfq-887p: ai-agent-automation workflow path traversal advisory landing page | Kitploit
Tools/GitHubGitHub/chaitanyagarware/cve-2026-54520
Vulnerability AnalysisWeb SecuritySupply Chain SecurityMisconfigurationLearning & EducationCurated Resources
GitHubchaitanyagarware/cve-2026-54520

CVE-2026-54520

CVE-2026-54520 / GHSA-cm8g-8jfq-887p: ai-agent-automation workflow path traversal advisory landing page

View Repository
11 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

CVE-2026-54520

ai-agent-automation workflow file step path traversal allowed read/write outside the expected directory.

Primary advisory: GHSA-cm8g-8jfq-887p
Researcher credit: @chaitanyagarware

At a Glance

FieldValue
CVECVE-2026-54520
GHSAGHSA-cm8g-8jfq-887p
ProjectvmDeshpande/ai-agent-automation
Packagebackend
Ecosystemnpm
SeverityHigh
CVSS8.1, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
WeaknessCWE-22
PublishedGitHub repository advisory: 2026-06-05
Patched versionv0.9.1
Public database statusGitHub repository advisory published; CVE.org, NVD, and OSV did not return records as of 2026-07-09

Summary

The workflow file step accepted a user-controlled step.path and resolved it against process.cwd() before reading or writing files. Because the backend did not enforce that the final resolved path stayed inside a safe workflow directory, traversal sequences could escape the expected filesystem boundary.

The affected component was backend/src/agents/executor.js.

Affected Versions

PackageAffected
backend<= 0.8.0

Fixed Versions

PackageFixed
backendv0.9.1

Public Database Coverage

Additional Public Mentions Found

  • chaitanyagarware/chaitanyagarware profile README references this CVE/GHSA.
  • chaitanyagarware/chaitanyagarware.github.io references this CVE/GHSA.
  • No broader GitHub issue/repo search results were returned for the exact CVE/GHSA terms during the 2026-07-09 sweep.

Disclosure Note

This repository is a public index and portfolio landing page. It intentionally summarizes the vulnerability and links to authoritative records instead of copying full proof-of-concept exploit scripts.

Download Tool
SourceStatusLink
GitHub repository advisoryPublishedGHSA-cm8g-8jfq-887p
CVE.orgNot indexed yetCVE detail
NVDNot indexed yetNVD detail
OSVNot indexed yetOSV lookup