CVE-2026-5595 | griptape-ai griptape 0.19.4 FileManagerTool path traversal
A vulnerability described as critical has been identified in griptape-ai griptape 0.19.4. Affected by this vulnerability is the function load_files_from_disk/list_files_from_disk/save_content_to_file/save_memory_artifacts_to_disk of the component FileManagerTool. Such manipulation leads to path traversal.
This vulnerability is listed as CVE-2026-5595. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.