Threat intelligence dashboard
CVE-2026-101080low

Tencent AI-Infra-Guard File Access dir_actions.py startsWith path traversal

A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skill_scan/tools/dir/dir_actions.py of the component File Access. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version 4.6.0 is able to mitigate this issue. The identifier of the patch is ac0384edc9dbea3b226edefcf50613bd8509134f. You should upgrade the affected component.

Risk score

2.4

CVSS 4.0

Vendor
Tencent
Product
AI-Infra-Guard
CWE
CWE-22
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

AI-Infra-Guard

Tencent

Version / rangeStatusType
4.5.0affected—
4.5.1affected—
4.5.2affected—
4.6.0affected—
4.6.1affected—
4.6.2affected—
4.6.0unaffected—

Technical metrics

2.4

CVSS 4.0

Severity
low
Source
VulDB
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

4.8

CVSS 3.1

Severity
medium
Source
VulDB
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C

4.8

CVSS 3.0

Severity
medium
Source
VulDB
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C

4.3

CVSS 2.0

Severity
medium
Source
VulDB
Vector
AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C