Two application vulnerabilities have exposed AGiXT and Bugsink servers to filesystem-level attacks that can lead to full host compromise. In AGiXT, advisory GHSA-5gfj-64gh-mgmw describes an authenticated path traversal flaw in the Essential Abilities Extension, rated CVSS 8.8, that lets an attacker escape intended directories and access files with the permissions of the AGiXT process. The issue allows arbitrary read, write, and delete operations against sensitive targets including environment files, configuration data, database credentials, cryptographic keys, /etc/shadow, and .ssh/id_rsa, creating high risk to confidentiality, integrity, and availability.
A separate flaw tracked as CVE-2026-40162 affects Bugsink and enables authenticated arbitrary file write or overwrite within the application's runtime permissions, with a CVSS 7.1 rating. The weakness can be used to overwrite Python source files or module initialization scripts so attacker-controlled code executes on restart or when a new worker is spawned, effectively turning file access into remote code execution. Both disclosures warn that deployments running with elevated privileges or broad filesystem access face the greatest danger, including persistence through locations such as cron directories, .ssh/authorized_keys, or application package paths, as well as exposure of secrets, telemetry, and backend credentials.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A high-severity vulnerability in Bugsink was publicly disclosed that allows authenticated arbitrary file write or overwrite within the application's permissions, creating a path to remote code execution and possible broader system compromise in misconfigured deployments.
A severe authenticated path traversal vulnerability in the AGiXT Essential Abilities Extension was publicly described, showing that attackers could read, write, and delete arbitrary files accessible to the AGiXT process and potentially achieve persistent remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.