PT-2026-76809 · Swe Agent+1 · Swe-Agent
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SWE-agent's trajectory inspector version 1.1.0
Description
The HTTP server fails to properly sanitize request paths in the '/trajectory/' endpoint, allowing the use of parent-directory ('..') references to perform path traversal. The server binds to all interfaces (0.0.0.0), uses wildcard CORS (Cross-Origin Resource Sharing), and lacks authentication. This allows an unauthenticated network client or a malicious web page to read files outside the intended directory. Access is limited to JSON files formatted as trajectories, which may contain repository contents, command output, and secrets or API keys.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Swe-Agent