MEDIUM6.5
PYSEC-2026-1597
Mage AI Path Traversal vulnerability
Details
Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "Pipeline Interaction" request
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/mage-ai
Introduced in:
0No fixed version published yet for mage-ai (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-45190[ADVISORY]
- https://github.com/mage-ai/mage-ai[PACKAGE]
- https://research.jfrog.com/vulnerabilities/mage-ai-pipeline-interaction-request-remote-arbitrary-file-leak-jfsa-2024-001039605[WEB]
- https://pypi.org/project/mage-ai[PACKAGE]
- https://github.com/advisories/GHSA-4mrc-w7jh-hx4j[ADVISORY]