CVE-2026-65698
MEDIUMVoid 1.3.4 Path Traversal via AI Agent File-Reading Tools
Title source: cnaDescription
Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injecting instructions into content the agent processes. Attackers can supply absolute paths or file:// URIs through the read_file, ls_dir, get_dir_tree, and search_* tools, which lack workspace confinement and bypass the approval gate, enabling silent exfiltration of sensitive files such as SSH private keys or cloud credentials via subsequent tool calls.
References (2)
Core 2
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/geo-chen/oss/blob/main/void.md
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/void-path-traversal-via-ai-agent-file-reading-tools
Scores
CVSS v3
5.3
EPSS
0.0035
EPSS Percentile
27.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
voideditor/void
< 1.3.4
Published
Jul 23, 2026
Tracked Since
Jul 23, 2026