Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.5 PyPI

python-a2a has a path traversal in the create_workflow function

GHSA-rp38-pj7h-r8q2 · CVE-2025-6167 · PYSEC-2025-64

Published · Modified

Description

A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function create_workflow of the file python_a2a/agent_flow/server/api.py. The manipulation leads to path traversal. Upgrading to version 0.5.6 is able to address this issue. It is recommended to upgrade the affected component.

Ready to move

Start Securing

Free, no credit card | First findings in minutes