PT-2026-84912 · Hkuds · Ai-Trader
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
HKUDS AI-Trader versions up to d03ff6c056b32ced735adf7c19ed8175adb1c8df
Description
A business logic error exists in the
selfRegister API endpoint within the service/server/routes agent.py file. Remote manipulation of the initial balance argument allows an attacker to inflate the absolute cash and equity values. While this does not result in artificial percentage returns because the profit percent for display() function and the return pct logic in challenge scoring normalize against the starting cash, it enables the manipulation of leaderboard rankings in the simulated game environment.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Restrict the use of the
initial balance parameter in the selfRegister API endpoint to prevent unauthorized balance inflation.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ai-Trader