In XLANG OpenAgents through fe73ac4, the allowed_file protection mechanism can be bypassed by using an incorrect file extension for the nature of the file content.
A product requires authentication, but the product has an alternate path or channel that does not require authentication.