CVE-2026-5595Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in griptape-ai griptape 0.19.4. Affected by this vulnerability is the function load_files_from_disk/list_files_from_disk/save_content_to_file/save_memory_artifacts_to_disk of the component FileManagerTool. Such manipulation leads to path traversal. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-05); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-04-05: 2Mentions · 2026-04-09: 2Technical Details · 2026-04-09: 204-0504-09
Signal classification1 categories
Disclosure
4100.0%
Referenced assets2 URLs
By indicator
Full discourse4 posts
  • NY-squared AI@NYsquaredAI
    Disclosure

    AIエージェントの「ファイル操作ツール」にパス検証ゼロ。 プロンプトインジェクション1発で ../../../etc/passwdが読める。 CVE-2026-5595(griptape-ai 0.19.4) ベンダー無応答・パッチ未提供。 エージェントにツールを渡す=攻撃面を渡す。 入力検証はLLMの外側で。 #AIセキュリティ #LLM

    Post summary

    CVE‑2026‑5595 in griptape‑ai 0.19.4 allows path traversal via prompt injection, enabling reading /etc/passwd; the vendor has not responded and no patch is available.

    1001073
    29 followersView on X
  • NY-squared AI@NYsquaredAI
    Disclosure

    AI agent's FileManagerTool: zero path sanitization. One prompt injection = full filesystem access via ../ traversal. CVE-2026-5595 (griptape-ai 0.19.4) Vendor unresponsive. No patch. Giving agents tools without input validation = giving attackers your filesystem. #AISecurity

    Post summary

    The tweet discloses CVE‑2026‑5595, a path‑traversal flaw in Griptape‑AI's FileManagerTool, highlights the lack of input sanitization, and notes the vendor has yet to issue a patch.

    0000058
    29 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5595 A security vulnerability has been detected in griptape-ai griptape 0.19.4. Affected by this vulnerability is the function load_files_from_disk/list_files_from_disk/save… https://www.cve.org/CVERecord?id=CVE-2026-5595 ----- Traducción: CVE-2026-5595 Se … http://infoflow.cloud`

    Post summary

    CVE-2026-5595 has been identified in griptape‑ai griptape 0.19.4, affecting certain file load and save functions; no proof‑of‑concept, exploit, active exploitation, or patch information is provided.

    0000036
    63 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5595 A security vulnerability has been detected in griptape-ai griptape 0.19.4. Affected by this vulnerability is the function load_files_from_disk/list_files_from_disk/save… https://www.cve.org/CVERecord?id=CVE-2026-5595

    Post summary

    The post reports the detection of CVE-2026-5595 in griptape‑ai griptape 0.19.4, noting affected functions but provides no further technical or exploit details.

    00000445
    56.8K followersView on X

Explore more