CVE-2026-53536 is a vulnerability in the Activepieces open source AI workflow automation platform. Prior to version 0.83.0, the /v1/step-files/signed download endpoint did not properly verify the token's audience and lacked a null-check on the decoded fileId, allowing any caller with a valid Activepieces JWT to receive a step-file belonging to another tenant. This issue allows for unauthorized access to s [truncated]
CVE-2026-53535 is a MEDIUM severity vulnerability in Activepieces, an open-source AI workflow automation platform. The git-sync feature clones a user-configured Git repository into a temporary directory on the server. Prior to version 0.82.0, two weaknesses allowed writes to escape the intended workspace and land on arbitrary paths on the host filesystem. An attacker with WRITE_PROJECT_RELEASE permission [truncated]
CVE-2026-12813 is a server-side request forgery (SSRF) vulnerability detected in activepieces up to version 0.83.0. The vulnerability affects the handleUrlFile function in the /packages/server/engine/src/lib/variables/processors/file.ts file. This issue allows for remote exploitation and has a publicly available exploit. The CVSS score is 2.1, indicating a low severity. The vendor, Unknown Vendor, was con [truncated]