Executive brief
HKUDS AI-Trader is an automated trading simulation platform. A vulnerability in the account registration endpoint allows attackers to manipulate the initial account balance parameter, inflating displayed equity and leaderboard rankings in the simulated game environment without affecting actual percentage returns or core trading logic.
Technical details
The vulnerability is a business logic error in the selfRegister API endpoint (service/server/routes_agent.py) where insufficient validation on the initial_balance parameter permits remote attackers to inject arbitrary values. Although profit calculations normalize against the inflated starting capital and thus prevent artificial percentage return inflation, the absolute cash/equity display is affected, enabling leaderboard manipulation and cosmetic fraud in a simulated trading environment. The attack requires network access to the API endpoint but no authentication. The fix status is unclear due to the rolling release model employed by the project.
Affected products
- HKUDS AI-Trader up to d03ff6c056b32ced735adf7c19ed8175adb1c8df
Timeline
- 2026-03-14: disclosed: Vulnerability disclosed to developer
- 2026-09-03: advisory: CVE-2026-85030 published