Description
An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.
References
github.com/...ob/v0.8.7/python/api/download_work_dir_file.py
www.cve.org/CVERecord?id=CVE-2025-6166
github.com/agent0ai/agent-zero/issues/687