← All research

GHSA-p347-7m45-694r

Arbitrary file read via LocalFileAgent file pointers with insecure agents disabled

01Record

IdentifierGHSA-p347-7m45-694r
ProjectHuginn
ComponentLocalFileAgent#get_io
CWECWE-22
CVSS9.6
Disclosed2026-09-08
Endor referenceENDOR-VUL-2026-27082

02Detail

Description: LocalFileAgent refuses to check, watch or write unless ENABLE_INSECURE_AGENTS is set, but its get_io method opened any file it was handed regardless. Any authenticated user could create a LocalFileAgent and supply a file pointer naming it to a consuming agent such as ReadFileAgent, CsvAgent or PostAgent, through an event or a dry run. Affects versions up to 2026.08.27; fixed in 2026.09.08.

Impact: Arbitrary File Read, Privilege Escalation. Files are read with the privileges of the Huginn process. Reading .env exposes APP_SECRET_TOKEN, which allows forging an administrator session cookie and taking over the instance.

Discovered by Peyton Kennedy (p80n), Infinit3i.