SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-81030

MEDIUM · CVSS 6.5 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Mage AI's browser-items API is vulnerable as it allows users with the Viewer role to read any file accessible by the server process by supplying an absolute path, bypassing the intended permission model. This flaw arises from the lack of path containment in the BrowserItemResource, which could lead to unauthorized data exposure. Organizations using Mage AI should prioritize addressing this vulnerability, particularly those with sensitive data or strict access controls, to mitigate potential information leaks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81030
Severity
MEDIUM
CVSS
6.5
EPSS
0.39%

Original NVD Description

Mage AI does not confine the paths accepted by its browser-items API to the project directory. BrowserItemResource in mage_ai/api/resources/BrowserItemResource.py passes a caller-supplied path to the filesystem read and write helpers without calling the containment helper that the sibling FileContentResource and FileResource classes both use, so the resource contains no such call while those two contain several. A user holding the Viewer role, which grants read access within the project and nothing outside it, can therefore read any file the server process can read by supplying an absolute path. The permission model that would otherwise separate roles is not consulted for this route in the default configuration, because the setting that enables it defaults to false. Callers holding the Editor role additionally write through the same unconfined path, though that role is already able to execute code by design, so the boundary crossed by this flaw is the read available to the Viewer role.