CVE-2026-58173
Vibe-Trading before 0.1.10 contains a path traversal vulnerability that allows attackers to write files outside the intended memory root dir
CVSS
6.5
Medium
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Published: Jun 30, 2026 · Last modified: Jul 14, 2026 · CWE-22
0.3%EPSS · 30 days0.3%
2026-07-012026-07-21
Vibe-Trading before 0.1.10 contains a path traversal vulnerability that allows attackers to write files outside the intended memory root directory by supplying a malicious memory_type value containing path traversal sequences through the remember tool. Attackers can manipulate the memory_type parameter in the persistent memory store to cause the application to write arbitrary Markdown files to unintended locations on the filesystem.
- github.comhttps://github.com/HKUDS/Vibe-Trading/pull/257
- github.comhttps://github.com/HKUDS/Vibe-Trading/pull/257
- github.comhttps://github.com/HKUDS/Vibe-Trading/pull/257
- github.comhttps://github.com/HKUDS/Vibe-Trading/pull/257
- github.comhttps://github.com/HKUDS/Vibe-Trading/pull/257
- github.comhttps://github.com/HKUDS/Vibe-Trading/pull/257
- github.comhttps://github.com/HKUDS/Vibe-Trading/pull/257
- github.comhttps://github.com/HKUDS/Vibe-Trading/pull/257
- github.comhttps://github.com/HKUDS/Vibe-Trading/releases/tag/v0.1.10
- www.vulncheck.comhttps://www.vulncheck.com/advisories/vibe-trading-path-traversal-via-persistent-memory-type
- github.comhttps://github.com/HKUDS/Vibe-Trading/pull/257
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-47425——
———Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `EntryPoint::FromStr` in `rattler_conda_types` performs only `.trim()` on the `command` field before the linker joins it onto the install prefix and writes an executable Python script. A malicious `noarch:python` package can ship an `info/link.json` with an entry-point name containing `..`, `/`, `\`, or an absolute path; the resulting file is written outside the prefix (or clobbers an existing in-prefix entry-point such as `bin/pip`) with mode `0o775` on Unix and a copied launcher `.exe` on Windows. This affects the default install path of `pixi install`, `mamba install` via py-rattler, `rattler-build`, and any other consumer of the `rattler` install crate; no flag or post-link-script opt-in is involved. Version 0.43.2 contains a fix for the issue.4hCVE-2026-47397——
———PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled content to arbitrary paths. `write_file` skips path validation when `workspace=None` (always `None` in production). Version 4.6.40 fixes the issue.3hCVE-2026-15791——
———A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory.4hCVE-2026-15789——
———A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.4hCVE-2026-157248.7 HIG—
———In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server.4hCVE-2026-648259.3 CRI—
———Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. Attackers can manipulate the 'name' field inside the uploaded archive's backup.json to supply an absolute path, causing pathlib.Path.__truediv__ to discard the configured backup directory prefix and write attacker-controlled content to arbitrary locations, with full filesystem access when the process runs as root.2h