Business Logic Errors in HKUDS AI-Trader from HKUDS
CVE-2026-85030
Key Information:
Badges
What is CVE-2026-85030?
A business logic error in HKUDS AI-Trader's selfRegister API Endpoint allows remote manipulation of the initial_balance argument in the routes_agent.py file. Attackers can exploit this flaw to cause significant inconsistencies in financial simulations. While the manipulation of initial_balance alters displayed values, it does not distort percent returns, presenting mainly a cosmetic issue. This issue has been publicly disclosed, and mitigating this vulnerability is crucial to protect the integrity of users' gameplay and rankings.
Affected Version(s)
AI-Trader d03ff6c056b32ced735adf7c19ed8175adb1c8df
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
