CVE-2025-67076

HIGH

agora-project < 25.10 - Unauthenticated Path Traversal via ExternalGetFile Action

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc controller and the ExternalGetFile action. Only files with an extension can be read.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0081
EPSS Percentile 52.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
agora-project/agora-project < 25.10
Published Jan 15, 2026
Tracked Since Feb 18, 2026