Path Traversal Vulnerability in Vibe-Trading by HKUDS
CVE-2026-58170

7.2HIGH

Key Information:

Vendor

Hkuds

Vendor
CVE Published:
30 June 2026

What is CVE-2026-58170?

A vulnerability in Vibe-Trading allows an attacker to manipulate the proposal file path by providing a malicious proposal identifier that includes path traversal sequences. This leads to the loading of a JSON file controlled by the attacker, which can then be used as a valid live trading mandate. The issue arises from the lack of sanitization in the file path construction and a flaw in ceiling validation checks, offering a method for adversaries to fully control trading mandates.

Affected Version(s)

Vibe-Trading 0 < 0.1.10

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chia Min Jun Lennon
.