File Path Traversal Vulnerability in Sublinear-Time-Solver and Consciousness-Explorer by Ruvnet
CVE-2026-55609

7.1HIGH

Key Information:

Vendor

Ruvnet

Vendor
CVE Published:
25 August 2026

What is CVE-2026-55609?

The Sublinear-Time-Solver and Consciousness-Explorer projects suffer from a file path traversal vulnerability due to improper handling of attacker-controlled file path parameters. The export_state and import_state tools in Consciousness-Explorer are vulnerable because they allow unvalidated input to file system operations, potentially allowing an attacker to read, write, or overwrite files accessible to the server. This flaw could compromise data confidentiality and integrity while causing service interruptions. This issue has been addressed in versions 1.1.2 for Consciousness-Explorer and 1.6.0 for Sublinear-Time-Solver.

Affected Version(s)

sublinear-time-solver < 1.6.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.