PT-2026-105771 · Git · Local-Operator

Publicado

2026-09-05

·

Atualizado

2026-09-05

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The /v1/chat/agents/{agent id}/edit endpoint in local-operator versions before 0.47.5 resolves the caller-supplied file path with expanduser().resolve() and reads it without checking that it lies inside the agent's workspace. An unauthenticated client with network access to the API can supply an absolute path or a path containing traversal sequences and obtain the contents of any file readable by the server process, which are placed in the model prompt and returned in the response.
Version 0.47.5 resolves server-side reads within the agent's configured workspace and rejects canonical paths outside it (including symlink and junction escapes) before any model call, adds an optional file content request field so clients can submit a buffer without host path resolution, and binds lop serve to 127.0.0.1 by default.

Correção

Path traversal

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

PYSEC-2026-4010

Produtos afetados

Local-Operator