Record summary

CVE-2025-55523 has a selected CVSS score of 3.5 (low); EIP currently links 1 Nuclei template.

Description

An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 15, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 21, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHAgent-Zero 0.8.0 - 0.9.4 - Arbitrary File DownloadCVSS 7.5

Agent-Zero v0.8.0 - 0.9.4 contains a path traversal caused by improper validation in /api/download_work_dir_file.py, letting attackers access unauthorized files, exploit requires crafted request.

Impact

Attackers can access unauthorized files, potentially exposing sensitive data or system information.

Remediation

Update to the latest version of Agent-Zero

WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2025agent-zerolfitraversalunauthvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Shodan: title:"Agent Zero"
FOFA: title="Agent Zero"

Source: ProjectDiscovery

References

4