CVE-2026-72713
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-22
Limitación incorrecta de nombre de ruta a un directorio restringido (Path Traversal)
Fecha de publicación:
11/08/2026
Última modificación:
11/08/2026
Descripción
*** Pendiente de traducción *** XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory segments in the `file_name` form field with no path containment check. Attackers can register an account without email verification, then submit crafted `file_name` values such as parent-directory traversal sequences to the `/workspace/file` handler to read host files including application secrets, database credentials, and system files outside the Docker sandbox.
Impacto
Puntuación base 4.0
8.70
Gravedad 4.0
ALTA
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://github.com/OpenBMB/XAgent
- https://github.com/OpenBMB/XAgent/commit/26f2b6edc75127af524f027c022b382967178e3a
- https://github.com/OpenBMB/XAgent/issues/429
- https://github.com/OpenBMB/XAgent/pull/432
- https://www.vulncheck.com/advisories/xagent-path-traversal-arbitrary-file-read-via-workspace-file
- https://github.com/OpenBMB/XAgent/issues/429



