Loading vulnerability details...
| Property | Value |
|---|---|
| Advisory ID | SGZ-2026-6957C |
| Severity | HIGH |
| CWE | CWE-22 |
| Confidence | 90% |
| Category | path_traversal |
| Exploitability | likely |
| Package | aggregate_entropy_stats@latest (python) |
| Location | tools/aggregate_entropy_stats.py:22-27 |
| Attack Vector | LOCAL |
| Attack Complexity | LOW |
| Privileges Required | LOW |
| Discovered By | SafeGuard Zero-Day AI Discovery Engine |
The script concatenates user-supplied directory and filename arguments directly to form file paths without any validation or sanitization. This allows an attacker to supply path traversal sequences (e.g., "../") in the directory or output filename arguments, causing the program to read arbitrary files via np.fromfile and write arbitrary data to any location via sum.tofile, potentially overwriting critical system files.
The vulnerability was identified in the file tools/aggregate_entropy_stats.py at lines 22-27 within the aggregate_entropy_stats package (version latest). Any code path that invokes these functions inherits this vulnerability.
File: tools/aggregate_entropy_stats.py (lines 22-27)
stats = np.fromfile(dir + fn, dtype=np.int32)
...
sum.tofile(dir+sys.argv[3])
The code above demonstrates the vulnerable pattern. This code is executed at runtime and can be directly exploited by an attacker with the appropriate access level.
Provide a crafted directory argument like "../" and a keyword that matches a chosen file, then set the output filename argument to "../../../../etc/passwd". The script will read the targeted file and write the aggregated stats to /etc/passwd, corrupting it.
Arbitrary file overwrite can lead to privilege escalation, service disruption, or persistent backdoors.
Sanitize and validate all path inputs. Use os.path.abspath and ensure the resulting path is within an allowed base directory. Construct paths with os.path.join and reject any path containing ".." or absolute paths. Additionally, limit file extensions and enforce read-only permissions for input files.
Advisory: SGZ-2026-6957C | Source: SafeGuard Zero-Day AI Discovery | Status: Candidate
This vulnerability was autonomously discovered by SafeGuard's AI-powered Zero-Day Discovery engine using TAOR (Think-Act-Observe-Repeat) agentic analysis on the package source code. It is not yet tracked in any public vulnerability database (CVE, NVD, GHSA, OSV). This finding should be triaged by a security engineer and, if confirmed, reported upstream to the package maintainer.
| Property | Value |
|---|---|
| Advisory ID | SGZ-2026-6957C |
| Severity | HIGH |
| CWE | CWE-22 |
| Confidence | 90% |
| Category | path_traversal |
| Exploitability | likely |
| Package | aggregate_entropy_stats@latest (python) |
| Location | tools/aggregate_entropy_stats.py:22-27 |
| Attack Vector | LOCAL |
| Attack Complexity | LOW |
| Privileges Required | LOW |
| Discovered By | SafeGuard Zero-Day AI Discovery Engine |
The script concatenates user-supplied directory and filename arguments directly to form file paths without any validation or sanitization. This allows an attacker to supply path traversal sequences (e.g., "../") in the directory or output filename arguments, causing the program to read arbitrary files via np.fromfile and write arbitrary data to any location via sum.tofile, potentially overwriting critical system files.
The vulnerability was identified in the file tools/aggregate_entropy_stats.py at lines 22-27 within the aggregate_entropy_stats package (version latest). Any code path that invokes these functions inherits this vulnerability.
File: tools/aggregate_entropy_stats.py (lines 22-27)
stats = np.fromfile(dir + fn, dtype=np.int32)
...
sum.tofile(dir+sys.argv[3])
The code above demonstrates the vulnerable pattern. This code is executed at runtime and can be directly exploited by an attacker with the appropriate access level.
Provide a crafted directory argument like "../" and a keyword that matches a chosen file, then set the output filename argument to "../../../../etc/passwd". The script will read the targeted file and write the aggregated stats to /etc/passwd, corrupting it.
Arbitrary file overwrite can lead to privilege escalation, service disruption, or persistent backdoors.
Sanitize and validate all path inputs. Use os.path.abspath and ensure the resulting path is within an allowed base directory. Construct paths with os.path.join and reject any path containing ".." or absolute paths. Additionally, limit file extensions and enforce read-only permissions for input files.
Advisory: SGZ-2026-6957C | Source: SafeGuard Zero-Day AI Discovery | Status: Candidate
This vulnerability was autonomously discovered by SafeGuard's AI-powered Zero-Day Discovery engine using TAOR (Think-Act-Observe-Repeat) agentic analysis on the package source code. It is not yet tracked in any public vulnerability database (CVE, NVD, GHSA, OSV). This finding should be triaged by a security engineer and, if confirmed, reported upstream to the package maintainer. This vulnerability involves weaknesses in
This high-severity vulnerability could allow attackers to gain unauthorized access, execute arbitrary code, or compromise data integrity. Prompt remediation is strongly recommended.
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior