GHSA-45p5-w2r8-mrfvunknown

deeptutor 1.4.0 contains a path traversal issue in EditFileTool.execute. Through the live...

Published
October 2, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (1)

📋 Description

deeptutor 1.4.0 contains a path traversal issue in EditFileTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to write or edit absolute paths outside the intended bot workspace.

🔗 References (4)