Path Traversal Vulnerability in Vibe-Trading by HKUDS
CVE-2026-58170
7.2HIGH
What is CVE-2026-58170?
A vulnerability in Vibe-Trading allows an attacker to manipulate the proposal file path by providing a malicious proposal identifier that includes path traversal sequences. This leads to the loading of a JSON file controlled by the attacker, which can then be used as a valid live trading mandate. The issue arises from the lack of sanitization in the file path construction and a flaw in ceiling validation checks, offering a method for adversaries to fully control trading mandates.
Affected Version(s)
Vibe-Trading 0 < 0.1.10
