PYSEC-2026-4010

    Dashboard / Vulnerabilities / PYSEC-2026-4010

    PYSEC-2026-4010

    Published: 5 Sept 2026Last Modified: 30 Sept 2026

    Summary: Arbitrary file read via workspace confinement bypass in local-operator /v1/chat/agents/{id}/edit

    Details: The `/v1/chat/agents/{agent_id}/edit` endpoint in local-operator versions before 0.47.5 resolves the caller-supplied `file_path` with `expanduser().resolve()` and reads it without checking that it lies inside the agent's workspace. An unauthenticated client with network access to the API can supply an absolute path or a path containing traversal sequences and obtain the contents of any file readable by the server process, which are placed in the model prompt and returned in the response. Version 0.47.5 resolves server-side reads within the agent's configured workspace and rejects canonical paths outside it (including symlink and junction escapes) before any model call, adds an optional `file_content` request field so clients can submit a buffer without host path resolution, and binds `lop serve` to 127.0.0.1 by default.

    Affected packages

    Package

    Name: local-operator

    Purl: pkg:pypi/local-operator

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    0.0.1
    0.0.10
    0.0.11
    0.0.12
    0.0.13
    0.0.14
    0.0.15
    0.0.16
    0.0.17
    0.0.18
    0.0.19
    0.0.2
    0.0.20
    0.0.21
    0.0.22
    0.0.23
    0.0.24
    0.0.25
    0.0.26
    0.0.27
    0.0.28
    0.0.29
    0.0.3
    0.0.4
    0.0.5
    0.0.6
    0.0.7
    0.0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    PYSEC-2026-4010 | CVE-DB