Executive brief
XAgent is an autonomous AI agent framework used for solving complex tasks. A path traversal vulnerability in the workspace file endpoint allows attackers who register an account (without email verification) to read arbitrary files from the host system, including sensitive configuration files, database credentials, and application secrets.
Technical details
The vulnerability is a path traversal flaw in the `/workspace/file` HTTP endpoint that fails to validate or sanitize the `file_name` form parameter. Unauthenticated attackers can self-register an account without email verification, then submit crafted file names containing parent-directory traversal sequences (e.g., `../../../etc/passwd`) to access files outside the intended workspace directory. The lack of path containment validation allows reading arbitrary files on the host, including files outside the Docker sandbox. A fix was published on 2026-07-31 in commit 26f2b6edc75127af524f027c022b382967178e3a.
Affected products
- OpenBMB XAgent <UNKNOWN>
Timeline
- 2026-08-11: disclosed
- 2026-07-31: patched