GHSA-rp38-pj7h-r8q2
MODERATECVE-2025-6167A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function createworkflow of the file pythona2a/agentflow/server/api.py. The manipulation leads to path traversal. Upgrading to version 0.5.6 is able to address this issue. It is recommended to upgrade the affected component.
- Affected
- < 0.5.6
- Fixed in
- 0.5.6
- Weakness
- CWE-22
- Published
- 2025-06-17
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereference