TEN Framework version 0.11.71 is affected by critical unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can exploit the /api/designer/v1/file-content endpoints via POST and PUT HTTP requests without any authentication. This allows reading of arbitrary files from the system or writing malicious content to sensitive system paths. Exploitation can lead to remote code execution through manipulation of authorized_keys files, cron jobs, or executable graph files. No credentials or prior access are required to exploit these vulnerabilities. The vulnerabilities are documented in the TEN Framework GitHub repository and tracked under CVE-2026-85688. The issue has been reported via a GitHub issue and a VulnCheck advisory. Organizations running TEN Framework 0.11.71 should treat this as a high-priority remediation.
/api/designer/v1/file-content