HIGHCVSS 7.5Vulnerability

CVE-2026-75482

SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassing the built-in path sanitization. The server binds all interfaces (0.0.0.0), applies wildcard CORS, and requires no authentication. An unauthenticated network client (or a malicious web page via CORS) can use path traversal sequences to read files outside the intended directory. Because the read sink parses targets as trajectory JSON, disclosure is constrained to JSON files shaped like a trajectory, which can contain repository contents, command output, and secrets/API keys.

Properties

severity
HIGH
cvss_severity
HIGH
cvss_score
7.5
retrieved_at
2026-09-25T15:10:02+00:00
score
7.5
last_source
NVD
cve_id
CVE-2026-75482
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
signal_observed_at
2026-09-25T15:10:02+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-17T21:16:50.833
last_modified
2026-09-24T20:06:30.133

Related Entities (2)

HAS_WEAKNESS (1)

→[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DESCRIBED_BY (1)

→[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75482 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal