Vulnerability PYSEC-2026-4010

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
25 days ago
September 05, 2026 at 07:44 AM UTC
Arbitrary file read via workspace confinement bypass in local-operator /v1/chat/agents/{id}/edit
0.0.1 - 0.47.4
0.0.1 - 0.47.4

Summary

Arbitrary file read via workspace confinement bypass in local-operator /v1/chat/agents/{id}/edit

Details

The /v1/chat/agents/{agent_id}/edit endpoint in local-operator versions before 0.47.5 resolves the caller-supplied file_path with expanduser().resolve() and reads it without checking that it lies inside the agent's workspace. An unauthenticated client with network access to the API can supply an absolute path or a path containing traversal sequences and obtain the contents of any file readable by the server process, which are placed in the model prompt and returned in the response.

Version 0.47.5 resolves server-side reads within the agent's configured workspace and rejects canonical paths outside it (including symlink and junction escapes) before any model call, adds an optional file_content request field so clients can submit a buffer without host path resolution, and binds lop serve to 127.0.0.1 by default.

Impacted packages

Timeline

Published
25 days ago
September 05, 2026 at 07:44 AM UTC
Fixed (0.47.5)
25 days ago
September 05, 2026 at 07:39 AM UTC
Last Modified
2 hours ago
September 30, 2026 at 04:46 PM UTC