Vulnerability PYSEC-2026-4009

Critical
CRITICAL RISK
CVSS Score: 9.1
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
25 days ago
September 05, 2026 at 07:43 AM UTC
Path traversal and arbitrary directory deletion/overwrite via agent profile import in local-operator
0.0.1 - 0.47.4
0.0.1 - 0.47.4

Summary

Path traversal and arbitrary directory deletion/overwrite via agent profile import in local-operator

Details

The /v1/agents/import endpoint and AgentRegistry.import_agent() in local-operator versions before 0.47.5 trust the id field inside agent.yml of an uploaded agent profile archive when constructing the destination directory. A crafted id containing directory traversal sequences makes shutil.rmtree and shutil.copy2 operate outside the agent registry, allowing an unauthenticated client with network access to the API to recursively delete arbitrary directories and write files with the privileges of the server process. Even without traversal, an imported archive could overwrite or delete existing local agent profiles.

Version 0.47.5 assigns a fresh server-generated identifier to every imported profile, never derives a filesystem path from archive metadata, creates destination directories exclusively, and binds lop serve to 127.0.0.1 by default.

Impacted packages

Timeline

Published
25 days ago
September 05, 2026 at 07:43 AM UTC
Fixed (0.47.5)
25 days ago
September 05, 2026 at 07:39 AM UTC
Last Modified
2 hours ago
September 30, 2026 at 04:46 PM UTC