VYPR

agentic-context-engine

by Agentic Context Engine

CVEs (1)

  • CVE-2026-29870HigMar 31, 2026
    risk 0.49cvss 7.6epss 0.01

    A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file writes via the checkpoint_dir parameter in OfflineACE.run. The save_to_file method in ace/skillbook.py fails to normalize or validate filesystem paths, allowing…