PT-2026-76809 · Swe Agent+1 · Swe-Agent

·

CVE-2026-75482

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SWE-agent's trajectory inspector version 1.1.0
Description The HTTP server fails to properly sanitize request paths in the '/trajectory/' endpoint, allowing the use of parent-directory ('..') references to perform path traversal. The server binds to all interfaces (0.0.0.0), uses wildcard CORS (Cross-Origin Resource Sharing), and lacks authentication. This allows an unauthenticated network client or a malicious web page to read files outside the intended directory. Access is limited to JSON files formatted as trajectories, which may contain repository contents, command output, and secrets or API keys.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75482

Affected Products

Swe-Agent