---
id: CVE-2026-51852
title: >-
  agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in
  python/helpers/file_browser.py:FileBrowser.save_file_b64
summary: >-
  agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in
  python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64
  method accepts user-controlled file paths without normalization or validation,
  allowin…
severity: none
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:17:11.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-51852'
references:
  - url: 'https://gist.github.com/Ro1ME/13af0869833757245685d2d390458664'
    label: cve@mitre.org
  - url: 'https://github.com/agent0ai/agent-zero/issues/1540'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.841Z'
---

## Overview

agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
