PT-2026-84912 · Hkuds · Ai-Trader

·

CVE-2026-85030

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions HKUDS AI-Trader versions up to d03ff6c056b32ced735adf7c19ed8175adb1c8df
Description A business logic error exists in the selfRegister API endpoint within the service/server/routes agent.py file. Remote manipulation of the initial balance argument allows an attacker to inflate the absolute cash and equity values. While this does not result in artificial percentage returns because the profit percent for display() function and the return pct logic in challenge scoring normalize against the starting cash, it enables the manipulation of leaderboard rankings in the simulated game environment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict the use of the initial balance parameter in the selfRegister API endpoint to prevent unauthorized balance inflation.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85030

Affected Products

Ai-Trader