GHSA-c39q-75j3-4qgfMediumCVSS 4.4

MoAI-ADK through 3.1.2 contains an improper link resolution vulnerability in the moai init...

Published
October 11, 2026
Last Modified
October 11, 2026

🔗 CVE IDs covered (1)

📋 Description

MoAI-ADK through 3.1.2 contains an improper link resolution vulnerability in the moai init template deployer that allows malicious repositories to overwrite files outside the project via a symlinked .moai-tmp staging path. Attackers can commit a symlink such as .claude/settings.json.moai-tmp so atomicWriteFile truncates and overwrites victim-writable files with MoAI template content.

🔗 References (7)