Qodo Qodo Gen IDE Path Traversal Vulnerability Allowing Arbitrary File Read

Vulnerability

A path traversal vulnerability has been identified in all versions of the Qodo Qodo Gen IDE. This vulnerability allows a threat actor to read arbitrary local files, both within and outside of current projects, on an end user's system. The issue can be exploited directly or through indirect prompt injection.

Impact

Exploitation of this vulnerability allows for arbitrary file read access on the user's system, bypassing normal directory restrictions.

Reproduction

To reproduce this vulnerability, create a GitHub repository containing a symbolic link to a file or directory outside of the project's allowed scope. Once the repository is cloned, the symbolic link will be created in the local project. Then, upload a README file with instructions that prompt Qodo Gen to access the linked files. When Qodo Gen processes the README, it will follow the instructions and exfiltrate the contents of the linked files to a remote server.

Added: Oct 17, 2025, 4:17 PM
Updated: Oct 17, 2025, 4:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.7
remediation
0.0
relevance
0.8
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.