CVE-2026-65698
Void 1.3.4 Path Traversal via AI Agent File-Reading Tools
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injecting instructions into content the agent processes. Attackers can supply absolute paths or file:// URIs through the read_file, ls_dir, get_dir_tree, and search_* tools, which lack workspace confinement and bypass the approval gate, enabling silent exfiltration of sensitive files such as SSH private keys or cloud credentials via subsequent tool calls.
| CWE | CWE-22 |
| Vendor | voideditor |
| Product | void |
| Published | Jul 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for voideditor void
Be the first to know when new medium vulnerabilities affecting voideditor void are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
voideditor / void
0 โค 1.3.4
References
Credits
George Chen