CVE-2026-42075

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in the skill download (fetch) command allows attackers to write files to arbitrary locations on the filesystem. The --out= flag accepts user-provided paths without validation, enabling directory traversal attacks that can overwrite critical system files or create files in sensitive location. This issue has been patched in version 1.69.3.
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-04 17:16

Updated : 2026-06-17 10:47


NVD link : CVE-2026-42075

Mitre link : CVE-2026-42075

CVE.ORG link : CVE-2026-42075


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')