CVE-2026-7784 PUBLISHED

RTGS2017 NagaAgent Skills Endpoint extensions.py path traversal

Assigner: VulDB
Reserved: 04.05.2026 Published: 04.05.2026 Updated: 04.05.2026

A vulnerability has been found in RTGS2017 NagaAgent up to 5.1.0. This issue affects some unknown processing of the file apiserver/routes/extensions.py of the component Skills Endpoint. Such manipulation of the argument Name leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.9

Product Status

Vendor RTGS2017
Product NagaAgent
Versions
  • Version 5.0 is affected
  • Version 5.1.0 is affected

Credits

  • CPT_Penner (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Path Traversal CWE