CVE-2026-54520: AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior
Summary
AI Agent Automation, a platform for managing AI workflows with scheduling and monitoring tools, has a vulnerability in versions before 0.9.1 where authenticated users can manipulate file paths to escape the intended workspace directory and read sensitive files or overwrite files that the application can access. The vulnerability occurs because the system doesn't verify that file paths stay within approved directories after resolving them.
Solution / Mitigation
Update to version 0.9.1 or later, which fixes the issue.
Vulnerability Details
8.1(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
network
low
low
none
September 17, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-54520
First tracked: September 17, 2026 at 08:07 PM
Classified by LLM (prompt v3) · confidence: 85%