CVE-2026-101080

Source
https://cve.org/CVERecord?id=CVE-2026-101080
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101080.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-101080
Published
2026-09-28T16:00:14Z
Modified
2026-09-29T03:45:46Z
Severity
  • 0.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Tencent AI-Infra-Guard File Access dir_actions.py startsWith path traversal
Details

A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skill_scan/tools/dir/dir_actions.py of the component File Access. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version 4.6.0 is able to mitigate this issue. The identifier of the patch is ac0384edc9dbea3b226edefcf50613bd8509134f. You should upgrade the affected component.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-22"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101080.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "4.5.2"
                },
                {
                    "last_affected":  "4.5.2"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/tencent/ai-infra-guard

Affected ranges

Type
GIT
Repo
https://github.com/tencent/ai-infra-guard
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "4.5.0"
        },
        {
            "last_affected":  "4.5.0"
        },
        {
            "introduced":  "4.5.1"
        },
        {
            "last_affected":  "4.5.1"
        },
        {
            "introduced":  "4.6.0"
        },
        {
            "last_affected":  "4.6.0"
        },
        {
            "introduced":  "4.6.1"
        },
        {
            "last_affected":  "4.6.1"
        },
        {
            "introduced":  "4.6.2"
        },
        {
            "last_affected":  "4.6.2"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

4.*
4.5.0
4.5.1
4.6.0
4.6.1
4.6.2
v4.*
v4.5.0
v4.5.1
v4.6.0
v4.6.1
v4.6.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101080.json"