CVE-2026-39981 affects AGiXT, a dynamic AI Agent Automation Platform, in versions prior to 1.9.2. The vulnerability exists in the safe_join() function within the essential_abilities extension, which fails to properly validate that resolved file paths remain confined to the designated agent workspace. This flaw allows authenticated attackers to exploit directory traversal sequences to read, write, or delete arbitrary files on the affected server. The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector, low attack complexity, and low privilege requirements. The impact is severe across all security dimensions: attackers can achieve high confidentiality impact through unauthorized file access, high integrity impact through file modification or deletion, and high availability impact through potential system disruption. There is no current evidence of active exploitation in the wild, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists. The EPSS score of 0.005 indicates lower predictive likelihood of exploitation compared to other CVEs, though organizations running AGiXT versions prior to 1.9.2 should prioritize patching given the high severity rating and the ease with which authenticated users could launch attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9.2CPE matchmatch criteria | cpe:2.3:a:agixt:agixt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.