VDB
Sign up
CRITICAL9.8

PYSEC-2025-64

Quick fix

PYSEC-2025-64 — python-a2a: upgrade to the fixed version with the command below.

pip install --upgrade 'python-a2a>=f486b53625698b7d03561d176dfe98f5d1528276'

Details

A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function create_workflow of the file python_a2a/agent_flow/server/api.py. The manipulation leads to path traversal. Upgrading to version 0.5.6 is able to address this issue. It is recommended to upgrade the affected component.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/python-a2a
Introduced in: 0Fixed in: f486b53625698b7d03561d176dfe98f5d1528276
Fixpip install --upgrade 'python-a2a>=f486b53625698b7d03561d176dfe98f5d1528276'

References