CVE-2026-101080

low

Description

A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skill_scan/tools/dir/dir_actions.py of the component File Access. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version 4.6.0 is able to mitigate this issue. The identifier of the patch is ac0384edc9dbea3b226edefcf50613bd8509134f. You should upgrade the affected component.

References

https://vuldb.com/vuln/410952/cti

https://vuldb.com/vuln/410952

https://vuldb.com/submit/931298

https://vuldb.com/cve/CVE-2026-101080

https://github.com/Tencent/AI-Infra-Guard/releases/tag/v4.6.0

https://github.com/Tencent/AI-Infra-Guard/pull/539

https://github.com/Tencent/AI-Infra-Guard/issues/538

https://github.com/Tencent/AI-Infra-Guard/commit/ac0384edc9dbea3b226edefcf50613bd8509134f

https://github.com/Tencent/AI-Infra-Guard/

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88341

Details

Source: Mitre, NVD

Published: 2026-09-28

Updated: 2026-09-28

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 4.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

Severity: Medium

CVSS v4

Base Score: 2.4

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Severity: Low

EPSS

EPSS: 0.00137