Junglewise Threat Intelligence

CVE-2026-26396: OpenBMB XAgent path traversal in workspace router

CVE-2026-26396 · Severity: info · CVSS 7.5 · Published 2026-07-13

Executive brief

OpenBMB XAgent, an autonomous agent framework, contains a security flaw that allows unauthorized access to files on the host server. By sending a specially crafted request, an attacker can bypass security boundaries to read sensitive system files or configuration data. This could lead to the exposure of private information and provide a foothold for further attacks on the organization's infrastructure.

Technical details

A path traversal vulnerability exists in OpenBMB XAgent versions up to and including 1.0.0. The flaw is located within the `file()` function in the `workspace.py` router, where the `file_name` (or `filename`) parameter is concatenated directly into a file path without sufficient sanitization or validation. A remote attacker can exploit this by providing a malicious string containing traversal sequences (e.g., `../../`) to escape the intended workspace directory. Successful exploitation allows the attacker to read arbitrary files on the server's filesystem that the application process has permissions to access. The vulnerability can be triggered via a POST request to the `/workspace/file` endpoint after establishing a valid interaction session.

Affected products

  • OpenBMB XAgent 1.0.0 and earlier

Timeline

  • 2026-06-18: disclosed: Initial vulnerability report shared via GitHub Gist.
  • 2026-07-13: advisory: CVE-2026-26396 published to the NVD.

References

Related threats