CVE-2026-42075

HIGH

Evolver: Path Traversal via `--out` flag in `fetch` command allows Arbitrary File Write

Title source: cna
STIX 2.1

Description

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in the skill download (fetch) command allows attackers to write files to arbitrary locations on the filesystem. The --out= flag accepts user-provided paths without validation, enabling directory traversal attacks that can overwrite critical system files or create files in sensitive location. This issue has been patched in version 1.69.3.

References (2)

Core 2
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/EvoMap/evolver/releases/tag/v1.69.3

Scores

CVSS v3 8.1
EPSS 0.0057
EPSS Percentile 42.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
evomap/evolver 0 - 1.69.3npm
EvoMap/evolver < 1.69.3
Published May 04, 2026
Tracked Since May 04, 2026