Path Traversal Vulnerability in OpenBMB XAgent Software
CVE-2026-26396
7.5HIGH
What is CVE-2026-26396?
The OpenBMB XAgent software version 1.0.0 and earlier is susceptible to a path traversal vulnerability. This issue arises in the file() function within the XAgent source code, specifically located in the workspace.py file. By manipulating the 'filename' input parameter, an attacker can concatenate arbitrary paths into the file path, bypassing access restrictions and leading to unintended file access. This vulnerability may potentially expose sensitive information stored on the server.
