What is CVE-2026-65698?
Void versions through 1.3.4 contain a path traversal vulnerability in the AI agent's file-reading tools. This allows network-adjacent attackers to read arbitrary files outside the open workspace by injecting instructions into processed content. Users are advised to update to the latest version immediately.
Azərbaycanca: Void platformasının 1.3.4-ə qədər olan versiyalarında AI agentinin fayl oxuma alətində path traversal zəifliyi mövcuddur. Bu, şəbəkəyə bitişik təcavüzkarlara agentin emal etdiyi məzmuna təlimatlar yeridərək, açıq iş sahəsindən kənarda ixtiyari host fayllarını oxumağa imkan verir. İstifadəçilərə dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of Void are affected by CVE-2026-65698?
Void versions through 1.3.4 are affected by this path traversal vulnerability.
How can an attacker exploit CVE-2026-65698?
A network-adjacent attacker can read arbitrary host files outside the open workspace by injecting instructions into content processed by the AI agent.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.