CVE-2026-65698: Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace
Summary
Void versions up to 1.3.4 have a path traversal vulnerability (a flaw where attackers can access files outside the intended directory by using special path tricks like absolute paths or file:// URIs) in its AI agent file-reading tools. Network-adjacent attackers (those on the same local network) can inject malicious instructions to read sensitive files like SSH private keys or cloud credentials without needing approval, potentially exposing them to unauthorized access.
Vulnerability Details
5.3(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
network
high
none
required
July 23, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-65698
First tracked: July 23, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 85%