


Perceptive Security
SOC/SIEM Consultancy

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in the skill download (fetch) command allow…
Published:
3 mei 2026 om 22:00:00
Alert date:
4 mei 2026 om 18:09:25
Source:
nvd.nist.gov
Emerging Technologies, Security Tools
CVE-2026-42075 affects Evolver, a GEP-powered self-evolving engine for AI agents. The vulnerability exists in versions prior to 1.69.3 and involves a path traversal flaw in the skill download (fetch) command. The --out= flag accepts user-provided paths without proper validation, allowing attackers to perform directory traversal attacks. This enables writing files to arbitrary filesystem locations, potentially overwriting critical system files or creating files in sensitive directories. The vulnerability has been patched in version 1.69.3.
Technical details
Mitigation steps:
Affected products:
Evolver
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42075
https://github.com/EvoMap/evolver/releases/tag/v1.69.3
https://github.com/EvoMap/evolver/security/advisories/GHSA-r466-rxw4-3j9j
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
