Path Traversal Vulnerability in SWE-agent's Trajectory Inspector HTTP Server
CVE-2026-75482

8.7HIGH

Key Information:

Vendor

Swe-agent

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-75482?

The SWE-agent's trajectory inspector is vulnerable due to its improper handling of HTTP requests in the /trajectory/ handler. It permits parent-directory references ('..'), enabling attackers to bypass path sanitization measures. This flaw allows an unauthenticated attacker, including those leveraging cross-origin resource sharing (CORS) from malicious web pages, to utilize path traversal sequences to access files located outside the intended directory structure. The server's configuration binds to all interfaces, applies wildcard CORS policies, and does not implement any authentication requirements. The resultant exposure is particularly significant as the read output is parsed as trajectory JSON, potentially leaking sensitive information such as repository contents, command outputs, and API keys.

Affected Version(s)

SWE-agent 0 <= 1.1.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

geo-chen
.