A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function create_workflow of the file python_a2a/agent_flow/server/api.py. The manipulation leads to path traversal. Upgrading to version 0.5.6 is able to address this issue. It is recommended to upgrade the affected component.
References
Link | Resource |
---|---|
https://github.com/themanojdesai/python-a2a/issues/40 | Exploit Issue Tracking |
https://github.com/themanojdesai/python-a2a/issues/40#issuecomment-2904804388 | Exploit Issue Tracking |
https://github.com/themanojdesai/python-a2a/releases/tag/v0.5.6 | Release Notes |
https://vuldb.com/?ctiid.312642 | Permissions Required VDB Entry |
https://vuldb.com/?id.312642 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.593613 | Third Party Advisory VDB Entry |
https://github.com/themanojdesai/python-a2a/issues/40 | Exploit Issue Tracking |
Configurations
History
02 Jul 2025, 19:36
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/themanojdesai/python-a2a/issues/40 - Exploit, Issue Tracking | |
References | () https://github.com/themanojdesai/python-a2a/issues/40#issuecomment-2904804388 - Exploit, Issue Tracking | |
References | () https://github.com/themanojdesai/python-a2a/releases/tag/v0.5.6 - Release Notes | |
References | () https://vuldb.com/?ctiid.312642 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.312642 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.593613 - Third Party Advisory, VDB Entry | |
First Time |
Themanojdesai python A2a
Themanojdesai |
|
CPE | cpe:2.3:a:themanojdesai:python_a2a:*:*:*:*:*:*:*:* |
17 Jun 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/themanojdesai/python-a2a/issues/40 - | |
Summary |
|
17 Jun 2025, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-17 07:15
Updated : 2025-07-02 19:36
NVD link : CVE-2025-6167
Mitre link : CVE-2025-6167
CVE.ORG link : CVE-2025-6167
JSON object : View
Products Affected
themanojdesai
- python_a2a
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')