Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Vibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging Live Trading Mandates
Vulnerability Description
Vibe-Trading before 0.1.10 builds the proposal file path by joining a caller-supplied proposal identifier onto the broker proposals directory without sanitization (agent/src/live/mandate/commit.py). A proposal identifier containing path traversal sequences causes the application to load an attacker-controlled JSON file as an authoritative live trading mandate. Combined with the file upload endpoint, an admitted caller can write a JSON file to a known location and traverse to it, and because the ceilings validation is skipped when ceilings are absent, the attacker fully controls the committed mandate.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
HKUDS Vibe-Trading 路径遍历漏洞
Vulnerability Description
HKUDS Vibe-Trading是HKUDS组织的一款基于情绪驱动的交易分析系统。 HKUDS Vibe-Trading 0.1.10之前版本存在路径遍历漏洞,该漏洞源于将调用者提供的提案标识符与代理提案目录拼接构建文件路径时未经清理,容易受到路径遍历攻击。
CVSS Information
N/A
Vulnerability Type
N/A