← back
CVE-2025-55523

CVE-2025-55523

CVSS 3.5 LOWEPSS 1.0%CWE-22
Vexday Risk Score
23Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 3.5EPSS 1.0%KEV nãoPoC Nuclei simMetasploit Patch
Lifecycle
21 Aug 2025Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
n/a · n/a