CVE-2025-55523
agent-zero agent-zero Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2025-55523 has a selected CVSS score of 3.5 (low); EIP currently links 1 Nuclei template.
Description
An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 15, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 21, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Agent-ZeroBrowse frdel / Agent-Zero | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHAgent-Zero 0.8.0 - 0.9.4 - Arbitrary File DownloadCVSS 7.5
Agent-Zero v0.8.0 - 0.9.4 contains a path traversal caused by improper validation in /api/download_work_dir_file.py, letting attackers access unauthorized files, exploit requires crafted request.
Impact
Attackers can access unauthorized files, potentially exposing sensitive data or system information.
Remediation
Update to the latest version of Agent-Zero
Source: ProjectDiscovery