An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.
https://www.cve.org/CVERecord?id=CVE-2025-6166
https://github.com/frdel/agent-zero/blob/v0.8.7/python/api/download_work_dir_file.py