PatchSiren

ag2ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ag2ai CVE published 2026-10-11

CVE-2026-108543

A vulnerability was determined in ag2ai ag2 up to 0.13.4, affecting the UserProxyAgent component's os.path.join function, allowing for path traversal attacks. The attack can be carried out remotely, and the exploit has been publicly disclosed. However, the vendor did not respond to early disclosure. This vulnerability has a medium severity level and requires immediate attention from defenders responsible [truncated]