Vulnerabilidad · Publicado 06/08/2026
Se identificó una vulnerabilidad alta en TinyAGI versión 0.0.20 que afecta la función collectFiles del componente Message API Endpoint, permitiendo la manipulación remota e inclusión de archivos arbitrarios. El exploit está disponible públicamente y representa un riesgo inmediato para infraestructuras que utilizan esta librería en aplicaciones de IA generativa. Empresas en LATAM que implementen TinyAGI en producción deben considerar este defecto como prioritario dado el acceso remoto sin autenticación requerida.
A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core/src/response.ts of the component Message API Endpoint. This manipulation causes file inclusion. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Score: 7.3/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-73
Publicado en NIST NVD.