Intel

AIKIDO-2026-312688

hackmyagent is vulnerable to Path Traversal

Path TraversalGHSA-44f3-xgp9-pvp2 Published 3 days ago

82

High Risk

This Affects:

JShackmyagent
0.6.0 - 0.28.0
Fixed in 0.29.0
Are you affected? Scan for Free

TL;DR

The bundled MCP server exposes a file-analysis tool that returns the contents of any absolute path it is given and can also write into arbitrary directories. Untrusted or prompt-injected input can drive the server to read sensitive files such as credentials and SSH keys or to place files outside the workspace. The fix requires a declared root and confines all operations with path traversal and symlink protections.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run the bundled MCP server exposing the file-analysis tool to untrusted or prompt-influenced input.

Background info

hackmyagent is vulnerable to Path Traversal in versions 0.6.0 - 0.28.0.

How to fix this

Upgrade the hackmyagent library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform