Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skill_scan/tools/dir/dir_actions.py of the component File Access. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version 4.6.0 is able to mitigate this issue. The identifier of the patch is ac0384edc9dbea3b226edefcf50613bd8509134f. You should upgrade the affected component. | |
| Title | Tencent AI-Infra-Guard File Access dir_actions.py startsWith path traversal | |
| First Time appeared |
Tencent
Tencent ai-infra-guard |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:tencent:ai-infra-guard:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tencent
Tencent ai-infra-guard |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-28T17:36:43.700Z
Reserved: 2026-09-27T18:14:50.850Z
Link: CVE-2026-101080
Updated: 2026-09-28T17:36:36.790Z
Status : Received
Published: 2026-09-28T16:17:12.820
Modified: 2026-09-28T18:17:16.200
Link: CVE-2026-101080
No data.
OpenCVE Enrichment
Updated: 2026-09-28T18:30:04Z