Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.9

OpenBMB XAgent allows attackers to access sensitive files

CVE-2026-3954
Summary

A weakness in OpenBMB XAgent allows remote attackers to access sensitive files on a server. This could lead to unauthorized access to confidential data. It's recommended to update to the latest version of OpenBMB XAgent or contact the developers for further assistance.

Original title
A weakness has been identified in OpenBMB XAgent 1.0.0. Affected by this vulnerability is the function workspace of the file XAgentServer/application/routers/workspace.py. This manipulation of the ...
Original description
A weakness has been identified in OpenBMB XAgent 1.0.0. Affected by this vulnerability is the function workspace of the file XAgentServer/application/routers/workspace.py. This manipulation of the argument file_name causes path traversal. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
nvd CVSS2.0 6.4
nvd CVSS3.1 6.5
nvd CVSS4.0 6.9
Vulnerability type
CWE-22 Path Traversal
Published: 11 Mar 2026 · Updated: 13 Mar 2026 · First seen: 11 Mar 2026