PYSEC-2026-4009

    Dashboard / Vulnerabilities / PYSEC-2026-4009

    PYSEC-2026-4009

    Published: 5 Sept 2026Last Modified: 30 Sept 2026

    Summary: Path traversal and arbitrary directory deletion/overwrite via agent profile import in local-operator

    Details: The `/v1/agents/import` endpoint and `AgentRegistry.import_agent()` in local-operator versions before 0.47.5 trust the `id` field inside `agent.yml` of an uploaded agent profile archive when constructing the destination directory. A crafted `id` containing directory traversal sequences makes `shutil.rmtree` and `shutil.copy2` operate outside the agent registry, allowing an unauthenticated client with network access to the API to recursively delete arbitrary directories and write files with the privileges of the server process. Even without traversal, an imported archive could overwrite or delete existing local agent profiles. Version 0.47.5 assigns a fresh server-generated identifier to every imported profile, never derives a filesystem path from archive metadata, creates destination directories exclusively, and binds `lop serve` to 127.0.0.1 by default.

    Affected packages

    Package

    Name: local-operator

    Purl: pkg:pypi/local-operator

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    0.0.1
    0.0.10
    0.0.11
    0.0.12
    0.0.13
    0.0.14
    0.0.15
    0.0.16
    0.0.17
    0.0.18
    0.0.19
    0.0.2
    0.0.20
    0.0.21
    0.0.22
    0.0.23
    0.0.24
    0.0.25
    0.0.26
    0.0.27
    0.0.28
    0.0.29
    0.0.3
    0.0.4
    0.0.5
    0.0.6
    0.0.7
    0.0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    PYSEC-2026-4009 | CVE-DB