MEDIUM6.5
PYSEC-2026-1601
Mage AI Path Traversal vulnerability
Details
Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "File Content" request
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/mage-ai
Introduced in:
0No fixed version published yet for mage-ai (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-45188[ADVISORY]
- https://github.com/mage-ai/mage-ai[PACKAGE]
- https://research.jfrog.com/vulnerabilities/mage-ai-file-content-request-remote-arbitrary-file-leak-jfsa-2024-001039603[WEB]
- https://pypi.org/project/mage-ai[PACKAGE]
- https://github.com/advisories/GHSA-v9wr-8wrm-h6p7[ADVISORY]