Path Traversal Vulnerability in Vibe-Trading Software by HKUDS
CVE-2026-58173
6MEDIUM
What is CVE-2026-58173?
Vibe-Trading versions prior to 0.1.10 are susceptible to a path traversal vulnerability. This allows attackers to manipulate the memory_type parameter within the persistent memory store, enabling them to write arbitrary Markdown files to locations outside the intended memory root directory. By providing a specially crafted malicious value, attackers can exploit this vulnerability through the remember tool, potentially leading to unauthorized file access and manipulation on the affected systems.
Affected Version(s)
Vibe-Trading 0 < 0.1.10
