PT-2026-53922 · Unknown · Vibe-Trading
CVE-2026-58171
·
Published
2026-06-30
·
Updated
2026-07-01
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Vibe-Trading versions prior to 0.1.10
Description
The application constructs the swarm run directory by joining a caller-supplied run identifier to the runs base directory without proper validation in the
run dir() function located in agent/src/swarm/store.py. A crafted run identifier provided through the MCP swarm tools allows for path traversal, enabling the application to read arbitrary run.json files outside the intended runs directory and overwrite existing run.json files at the traversed locations.Recommendations
Update Vibe-Trading to version 0.1.10 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vibe-Trading