PT-2026-70827 · Xagent · Xagent

·

CVE-2026-72713

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions XAgent (affected versions not specified)
Description A path traversal issue exists in the workspace file endpoint. This allows users who are self-registered or using default credentials to read arbitrary files on the host system. The flaw occurs because the /workspace/file endpoint does not perform path containment checks on the file name form field. An attacker can register an account without email verification and provide parent-directory traversal sequences in the file name variable to access sensitive data outside the Docker sandbox, such as application secrets, database credentials, and system files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72713

Affected Products

Xagent