PT-2026-53922 · Unknown · Vibe-Trading

CVE-2026-58171

·

Published

2026-06-30

·

Updated

2026-07-01

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Vibe-Trading versions prior to 0.1.10
Description The application constructs the swarm run directory by joining a caller-supplied run identifier to the runs base directory without proper validation in the run dir() function located in agent/src/swarm/store.py. A crafted run identifier provided through the MCP swarm tools allows for path traversal, enabling the application to read arbitrary run.json files outside the intended runs directory and overwrite existing run.json files at the traversed locations.
Recommendations Update Vibe-Trading to version 0.1.10 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58171

Affected Products

Vibe-Trading