Back

MEDIUM

Void 1.3.4 Path Traversal via AI Agent File-Reading Tools

Published Jul 23, 2026

Description

Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injecting instructions into content the agent processes. Attackers can supply absolute paths or file:// URIs through the read_file, ls_dir, get_dir_tree, and search_* tools, which lack workspace confinement and bypass the approval gate, enabling silent exfiltration of sensitive files such as SSH private keys or cloud credentials via subsequent tool calls.

Affected products

Remediation

Red Hat statement

Void is vulnerable to path traversal in AI agent file tools that lack workspace confinement. A remote attacker who can get malicious instructions into agent-processed content (user interaction, high attack complexity) may read files outside the workspace via absolute paths or file:// URIs and exfiltrate them through later tool calls. Affects Void through 1.3.4.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 23, 2026
Updated Jul 24, 2026
Reserved Jul 22, 2026
CISA Vulnrichment
Updated Jul 24, 2026
NVD
Status Deferred
Modified Jul 24, 2026
Red Hat
Severity Moderate
Public date Jul 23, 2026
ENISA EUVD
Assigner VulnCheck
Published Jul 23, 2026
Updated Jul 24, 2026
Exploited since n/a
EUVD-2026-48312