Junglewise Threat Intelligence

CVE-2026-58173: HKUDS Vibe-Trading path traversal in persistent memory storage

CVE-2026-58173 · Severity: medium · CVSS 6.5 · Published 2026-06-30

Technologies: HKUDS Vibe-Trading. Vendors: HKUDS.

Executive brief

Vibe-Trading is an AI-powered trading platform that uses a 'remember' tool to store persistent data. A security flaw allows an attacker to bypass folder restrictions and write files to unauthorized locations on the server's hard drive. This could allow an attacker to overwrite system files or plant malicious data, potentially disrupting operations or compromising the integrity of the trading environment.

Technical details

A path traversal vulnerability exists in Vibe-Trading's PersistentMemory.add() function and the associated RememberTool. The application fails to validate the 'memory_type' parameter, which is used as a prefix in filename construction (e.g., f"{memory_type}_{slug}.md"). An authenticated attacker can provide a 'memory_type' containing traversal sequences (like '../') to escape the configured memory root directory. While the 'slug' portion of the filename is sanitized, the prefix is not, allowing arbitrary Markdown and frontmatter files to be written or overwritten anywhere the application has write permissions. This issue was addressed in version 0.1.10 by implementing a strict allowlist for memory categories.

Affected products

  • HKUDS Vibe-Trading < 0.1.10

Timeline

  • 2026-06-18: disclosed: Fix PR submitted to GitHub repository
  • 2026-06-19: patched: Version 0.1.10 released
  • 2026-06-30: advisory: CVE-2026-58173 published

References

Related threats