CVE-2026-39981Disclosure(agixt / agixt)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch agixt agixt systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

AGiXT is a dynamic AI Agent Automation Platform. Prior to 1.9.2, the safe_join() function in the essential_abilities extension fails to validate that resolved file paths remain within the designated agent workspace. An authenticated attacker can use directory traversal sequences to read, write, or delete arbitrary files on the server hosting the AGiXT instance. This vulnerability is fixed in 1.9.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • agixt

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
agixt

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-09: 2Patch / Workaround · 2026-04-09: 2Technical Details · 2026-04-09: 204-09
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-39981: HIGH] Critical security update: AGiXT's safe_join() function has a vulnerability pre-1.9.2, allowing attackers to access, modify, or delete files. Update to 1.9.2 to fix this issue.#cve,CVE-2026-39981,#cybersecurity https://cvefind.com/CVE-2026-39981

    Post summary

    The post announces a high‑severity vulnerability in AGiXT's safe_join() function affecting versions before 1.9.2, and urges users to update to 1.9.2 to resolve the issue.

    0000038
    619 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39981 AGiXT is a dynamic AI Agent Automation Platform. Prior to 1.9.2, the safe_join() function in the essential_abilities extension fails to validate that resolved file pa… https://www.cve.org/CVERecord?id=CVE-2026-39981

    Post summary

    The entry discloses a path‑traversal vulnerability in AGiXT’s safe_join function that existed before version 1.9.2, implying a patch in that release, but no PoC or exploit details are provided.

    0000096
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appagixtagixt---

Explore more