CVE Feed

    Dashboard / CVE / CVE-2026-72713

    CVE-2026-72713

    XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory segments in the `file_name` form field with no path containment check. Attackers can register an account without email verification, then submit crafted `file_name` values such as parent-directory traversal sequences to the `/workspace/file` handler to read host files including application secrets, database credentials, and system files outside the Docker sandbox.

    Published:Aug 11, 2026
    Last Modified:Aug 12, 2026
    EPS:Aug 11, 2026
    EPSS Score:0.00702
    CVSS Score:7.5

    Affected Products

    Vendor
    Openbmb
    Product
    Xagent

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High