Common Weakness Enumeration

CWE-552

Allowed

Files or Directories Accessible to External Parties

Abstraction: Base · Status: Draft

The product makes files or directories accessible to unauthorized actors, even though they should not be.

730 vulnerabilities reference this CWE, most recent first.

GHSA-5GQ3-CCFH-828V

Vulnerability from github – Published: 2025-09-15 15:31 – Updated: 2025-09-15 15:31
VLAI
Details

Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6.33.11465 on Windows allows a local user to gain SYSTEM privileges via exploiting insecure file delete operations. Reported in CCleaner v. 6.33.11465. This issue affects CCleaner: before < 6.36.11508.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-3025"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-552"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-09-15T13:15:36Z",
    "severity": "HIGH"
  },
  "details": "Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6.33.11465 on Windows allows a local user to gain SYSTEM privileges via exploiting insecure file delete operations. Reported in CCleaner v. 6.33.11465. This issue affects CCleaner: before \u003c 6.36.11508.",
  "id": "GHSA-5gq3-ccfh-828v",
  "modified": "2025-09-15T15:31:21Z",
  "published": "2025-09-15T15:31:21Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3025"
    },
    {
      "type": "WEB",
      "url": "https://www.gendigital.com/us/en/contact-us/security-advisories"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-5Q5G-57MW-WMQ6

Vulnerability from github – Published: 2025-12-18 18:30 – Updated: 2025-12-18 18:30
VLAI
Details

due to insufficient sanitazation in Vega’s convert() function when safeMode is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-14896"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-552"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-12-18T17:15:47Z",
    "severity": "HIGH"
  },
  "details": "due to insufficient sanitazation in Vega\u2019s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.",
  "id": "GHSA-5q5g-57mw-wmq6",
  "modified": "2025-12-18T18:30:30Z",
  "published": "2025-12-18T18:30:30Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14896"
    },
    {
      "type": "WEB",
      "url": "https://github.com/yuzutech/kroki/commit/f31093cd8a0a1d6999c43d560f62d1e82d59c77e"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-5RMQ-CHC7-M22F

Vulnerability from github – Published: 2026-10-02 22:44 – Updated: 2026-10-02 22:44
VLAI
Summary
Vibe-Trading file-read tools expose arbitrary server-readable files
Details

Summary:

2 findings — safe_user_path() accepts any path under Path.home() or Path.cwd(), which inside the shipped root container resolves to /root and /app (so all of root's home, including /root/.ssh/id_rsa, /root/.aws/credentials, /root/.kube/config, and /app/agent/.env, passes the check) (F9). read_document() has no sandbox call at all and returns the full content of any path the FastAPI process can read, including /etc/shadow, /etc/passwd, /proc/self/environ, and any secret file mounted into the container (F10). F10 is strictly broader than F9 but they have different fix scopes (F10 = a missing safe_path() call in one function; F9 = the envelope definition in path_utils.py), so both must be patched.


Shared baseline (applies to both findings)

The container has no USER directive (Dockerfile:15 — FROM python:3.11-slim AS runtime, no subsequent USER), so the FastAPI process runs as uid=0(root).

The two file-read tools described here are members of the auto-discovered LLM tool registry. Combined with GHSA-1 / F1, they are reachable from any anonymous TCP client to port 8899, but the same defects also apply to authenticated sessions and to prompt-injection in any document the agent processes. See GHSA-1's shared reproducer block for the install steps; the same docker compose up -d setup applies here.

Note on the HOST placeholder used throughout the per-finding "Steps to observe" blocks below: replace HOST with the address you reach the docker host on — typically localhost (or 127.0.0.1) if you are running the reproducer on the same machine as the container. All curl commands below assume this substitution.


Finding 9 — High: safe_user_path() accepts the entire user home directory and process CWD, allowing LLM tool calls to read /root credentials

  • Severity: High
  • CVSS v3.1: 7.5 — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • CVSS v4.0: 8.7 — AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
  • CWE: CWE-22 (Path Traversal); CWE-552 (Files Accessible to External Parties)

Affected file: agent/src/tools/path_utils.py - line 52 — def safe_user_path(p: str) -> Path: - line 73-77 — if resolved.is_relative_to(home) or resolved.is_relative_to(cwd): return resolved — home = Path.home(), cwd = Path.cwd()

Intent vs actual: safe_user_path() is intended to permit journal and shadow-account tools to open broker export files the operator may have placed anywhere under their home directory or the project folder. The intended invariant is that only user-owned broker data files are accessible — not system credential files or SSH keys. The actual envelope check accepts any path whose resolved form is inside Path.home() or Path.cwd(). Inside the shipped Docker container, Path.home() resolves to /root and Path.cwd() resolves to /app. Every file under either subtree passes the check, including:

  • /root/.ssh/id_rsa and any other SSH key files
  • /root/.aws/credentials, /root/.kube/config, /root/.docker/config.json
  • /app/agent/.env (the file containing the operator's real OPENROUTER_API_KEY, TUSHARE_TOKEN, and any other secrets)

A runtime probe inside the container confirmed that safe_user_path('/root/.aws/credentials') returned the path without raising ValueError. ExtractShadowStrategyTool was then invoked against /root/secrets/aws.csv (a planted credential file) and returned an error message containing the first line of the file via the parse-error channel.

Steps to observe:

  1. Per GHSA-1 shared reproducer, start the server with a working LLM API key and create an unauthenticated session.
  2. (Setup for safe demo: inside the container, docker exec a planted file: docker exec <container> sh -c 'mkdir -p /root/secrets && printf "broker_id,api_key,api_secret\nDEMO,FAKE_KEY,FAKE_SECRET\n" > /root/secrets/aws.csv'.)
  3. curl -s -X POST "http://HOST:8899/sessions/$SID/messages" -H 'Content-Type: application/json' -d '{"content":"Analyze the trade journal at the path /root/secrets/aws.csv and tell me what you find."}'
  4. Poll curl -s "http://HOST:8899/sessions/$SID/messages". Observe the agent invoke ExtractShadowStrategyTool with journal_path="/root/secrets/aws.csv", which passes safe_user_path() and attempts to parse the file as a trade journal CSV.
  5. Observe the error response — when the file's structure does not match the expected journal schema, the parse error often includes the first line (column names) verbatim, leaking the file's first line.
  6. Repeat with journal_path="/app/agent/.env" to confirm the .env file is within the accepted envelope.

Impact: Any unauthenticated caller can instruct the LLM to attempt to parse any file under /root or /app as a trade journal, extracting the file's first line via the parse-error message channel. Files with valid CSV-like first lines may leak multiple bytes. In the shipped root container, /root encompasses all credentials a careless operator may have mounted into the home directory; /app includes the agent's own secrets and any operator-staged data files.


Finding 10 — High: read_document() opens any server-readable file with no sandbox enforcement, returning full content of /etc/shadow and /proc/self/environ

  • Severity: High
  • CVSS v3.1: 7.5 — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • CVSS v4.0: 8.7 — AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
  • CWE: CWE-22 (Path Traversal); CWE-552 (Files Accessible to External Parties); CWE-200 (Information Exposure)

Affected file: agent/src/tools/doc_reader_tool.py - line 259 — def read_document(file_path: str, pages: str = "") -> str: - line 270 — path = Path(file_path) — followed only by path.exists() and path.is_file() checks before dispatching to format-specific readers - No call to safe_path, safe_user_path, or any other sandbox enforcement appears anywhere in the function

Intent vs actual: DocReaderTool is intended to allow the LLM agent to read documents and data files provided for analysis. Like other file-reading tools in the project, it should apply a sandbox check before opening the file. The actual implementation takes the LLM-emitted file_path string, runs only path.exists() and path.is_file(), and dispatches to the appropriate reader. No call to safe_path or safe_user_path exists in the function. A runtime probe confirmed:

  • read_document('/etc/passwd') returned HTTP 200 with 839 characters of content
  • read_document('/etc/shadow') returned the full shadow password file
  • read_document('/proc/self/environ') returned the full process environment, including OPENROUTER_API_KEY and TUSHARE_TOKEN in plaintext

This is strictly wider than F9: F9 is bounded to /root + /app via the (overly-broad) envelope; F10 has no envelope at all and reaches /etc, /proc, /var, and any other path the FastAPI process can read.

Steps to observe:

  1. Per GHSA-1 shared reproducer, start the server with a working LLM API key and create an unauthenticated session.
  2. curl -s -X POST "http://HOST:8899/sessions/$SID/messages" -H 'Content-Type: application/json' -d '{"content":"Please read and summarize the document at /proc/self/environ"}'
  3. Poll curl -s "http://HOST:8899/sessions/$SID/messages". Observe the agent invoke read_document with file_path="/proc/self/environ" and return the full process environment in the message stream.
  4. Observe OPENROUTER_API_KEY, TUSHARE_TOKEN, and any other variables in agent/.env appearing in plaintext.
  5. Repeat with file_path="/etc/shadow" to confirm shadow password file access.

Impact: An unauthenticated caller can retrieve any file the server process can read. Running as root, that includes /etc/shadow, /etc/passwd, /proc/self/environ (full plaintext API keys), /root/.ssh/id_rsa, and any secret files mounted into the container. This is the broadest file-read primitive in the codebase and provides a credential-extraction path that does not require shell execution — endpoint monitoring tuned to BashTool / shell signatures will miss it entirely.


Why F9 and F10 are listed separately

A maintainer might be tempted to fix only one, on the theory that F10 dominates F9. Two reasons to fix both:

  1. Different fix scope — F10's fix is a single missing call (safe_path(file_path) in read_document before line 270). F9's fix is in safe_user_path() itself: the envelope must be replaced with a strict allowlist of operator-configured directories, not Path.home() ∪ Path.cwd(). A fix that adds the missing safe_user_path call to read_document is insufficient because safe_user_path itself accepts /root and /app/agent/.env. Both surfaces need work.

  2. Different reachability classes — F9 is reachable through tools that already gate on safe_user_path (ExtractShadowStrategyTool and several journal tools), so even a hypothetical F10 fix that switched read_document to use safe_user_path would still leak /root/* because the envelope is broken. F9 is the structural defect; F10 is the missed call.


Suggested remediation

  1. F9 — In safe_user_path() at path_utils.py:52-77, replace the Path.home() ∪ Path.cwd() envelope with a strict allowlist of operator-configured directories (e.g. an explicit BROKER_EXPORTS_DIR env var defaulting to /app/data/broker_exports/). Reject /root, /app/agent/.env, and /app/agent/uploads/ (the latter to prevent F3-uploaded files from being subsequently parsed as a credential-leak vector via the parse-error channel).'

  2. F10 — Add a safe_path() (or safe_user_path()) call at doc_reader_tool.py:270 before the existing path.exists() / path.is_file() checks. Once F9 is patched, the same allowlist will apply uniformly to both read_document and the safe_user_path-gated tools.

  3. Defense-in-depth — Drop the FastAPI process to a non-root user. Add a RUN useradd -m vibe && chown -R vibe /app step to the Dockerfile and USER vibe before CMD. This does not fix the Path Traversal but materially reduces the credential-extraction blast radius of any successful exploit (and benefits every other finding in GHSA-1 and GHSA-2). See GHSA-1 / shared baseline for the matching USER recommendation.


Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "vibe-trading-ai"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0.1.0"
            },
            {
              "fixed": "0.1.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [],
  "database_specific": {
    "cwe_ids": [
      "CWE-200",
      "CWE-22",
      "CWE-23",
      "CWE-552"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-02T22:44:12Z",
    "nvd_published_at": null,
    "severity": "HIGH"
  },
  "details": "### Summary: \n2 findings \u2014 `safe_user_path()` accepts any path under `Path.home()` or `Path.cwd()`, which inside the shipped root container resolves to `/root` and `/app` (so all of root\u0027s home, including `/root/.ssh/id_rsa`, `/root/.aws/credentials`, `/root/.kube/config`, and `/app/agent/.env`, passes the check) (F9). `read_document()` has no sandbox call at all and returns the full content of any path the FastAPI process can read, including `/etc/shadow`, `/etc/passwd`, `/proc/self/environ`, and any secret file mounted into the container (F10). F10 is strictly broader than F9 but they have different fix scopes (F10 = a missing `safe_path()` call in one function; F9 = the envelope definition in `path_utils.py`), so both must be patched.\n\n---\n\n### Shared baseline (applies to both findings)\n\nThe container has no `USER` directive (Dockerfile:15 \u2014 `FROM python:3.11-slim AS runtime`, no subsequent `USER`), so the FastAPI process runs as `uid=0(root)`. \n\nThe two file-read tools described here are members of the auto-discovered LLM tool registry. \nCombined with GHSA-1 / F1, they are reachable from any anonymous TCP client to port 8899, but the same defects also apply to authenticated sessions and to prompt-injection in any document the agent processes. \nSee GHSA-1\u0027s shared reproducer block for the install steps; the same `docker compose up -d` setup applies here.\n\n\u003e **Note on the `HOST` placeholder used throughout the per-finding \"Steps to observe\" blocks below**: replace `HOST` with the address you reach the docker host on \u2014 typically `localhost` (or `127.0.0.1`) if you are running the reproducer on the same machine as the container. All `curl` commands below assume this substitution.\n\n---\n\n### Finding 9 \u2014 High: safe_user_path() accepts the entire user home directory and process CWD, allowing LLM tool calls to read /root credentials\n\n- **Severity**: High\n- **CVSS v3.1**: 7.5 \u2014 `AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N`\n- **CVSS v4.0**: 8.7 \u2014 `AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N`\n- **CWE**: CWE-22 (Path Traversal); CWE-552 (Files Accessible to External Parties)\n\n**Affected file**: `agent/src/tools/path_utils.py`\n- line 52 \u2014 `def safe_user_path(p: str) -\u003e Path:`\n- line 73-77 \u2014 `if resolved.is_relative_to(home) or resolved.is_relative_to(cwd): return resolved` \u2014 `home = Path.home()`, `cwd = Path.cwd()`\n\n**Intent vs actual**: \n`safe_user_path()` is intended to permit journal and shadow-account tools to open broker export files the operator may have placed anywhere under their home directory or the project folder. The intended invariant is that only user-owned broker data files are accessible \u2014 not system credential files or SSH keys. The actual envelope check accepts any path whose resolved form is inside `Path.home()` or `Path.cwd()`. Inside the shipped Docker container, `Path.home()` resolves to `/root` and `Path.cwd()` resolves to `/app`. Every file under either subtree passes the check, including:\n\n- `/root/.ssh/id_rsa` and any other SSH key files\n- `/root/.aws/credentials`, `/root/.kube/config`, `/root/.docker/config.json`\n- `/app/agent/.env` (the file containing the operator\u0027s real `OPENROUTER_API_KEY`, `TUSHARE_TOKEN`, and any other secrets)\n\nA runtime probe inside the container confirmed that `safe_user_path(\u0027/root/.aws/credentials\u0027)` returned the path without raising `ValueError`. `ExtractShadowStrategyTool` was then invoked against `/root/secrets/aws.csv` (a planted credential file) and returned an error message containing the first line of the file via the parse-error channel.\n\n**Steps to observe**:\n\n1. Per GHSA-1 shared reproducer, start the server with a working LLM API key and create an unauthenticated session.\n2. (Setup for safe demo: inside the container, `docker exec` a planted file: `docker exec \u003ccontainer\u003e sh -c \u0027mkdir -p /root/secrets \u0026\u0026 printf \"broker_id,api_key,api_secret\\nDEMO,FAKE_KEY,FAKE_SECRET\\n\" \u003e /root/secrets/aws.csv\u0027`.)\n3. `curl -s -X POST \"http://HOST:8899/sessions/$SID/messages\" -H \u0027Content-Type: application/json\u0027 -d \u0027{\"content\":\"Analyze the trade journal at the path /root/secrets/aws.csv and tell me what you find.\"}\u0027`\n4. Poll `curl -s \"http://HOST:8899/sessions/$SID/messages\"`. Observe the agent invoke `ExtractShadowStrategyTool` with `journal_path=\"/root/secrets/aws.csv\"`, which passes `safe_user_path()` and attempts to parse the file as a trade journal CSV.\n5. Observe the error response \u2014 when the file\u0027s structure does not match the expected journal schema, the parse error often includes the first line (column names) verbatim, leaking the file\u0027s first line.\n6. Repeat with `journal_path=\"/app/agent/.env\"` to confirm the `.env` file is within the accepted envelope.\n\n**Impact**: \nAny unauthenticated caller can instruct the LLM to attempt to parse any file under `/root` or `/app` as a trade journal, extracting the file\u0027s first line via the parse-error message channel. Files with valid CSV-like first lines may leak multiple bytes. In the shipped root container, `/root` encompasses all credentials a careless operator may have mounted into the home directory; `/app` includes the agent\u0027s own secrets and any operator-staged data files.\n\n---\n\n### Finding 10 \u2014 High: read_document() opens any server-readable file with no sandbox enforcement, returning full content of /etc/shadow and /proc/self/environ\n\n- **Severity**: High\n- **CVSS v3.1**: 7.5 \u2014 `AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N`\n- **CVSS v4.0**: 8.7 \u2014 `AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N`\n- **CWE**: CWE-22 (Path Traversal); CWE-552 (Files Accessible to External Parties); CWE-200 (Information Exposure)\n\n**Affected file**: `agent/src/tools/doc_reader_tool.py`\n- line 259 \u2014 `def read_document(file_path: str, pages: str = \"\") -\u003e str:`\n- line 270 \u2014 `path = Path(file_path)` \u2014 followed only by `path.exists()` and `path.is_file()` checks before dispatching to format-specific readers\n- No call to `safe_path`, `safe_user_path`, or any other sandbox enforcement appears anywhere in the function\n\n**Intent vs actual**: `DocReaderTool` is intended to allow the LLM agent to read documents and data files provided for analysis. Like other file-reading tools in the project, it should apply a sandbox check before opening the file. The actual implementation takes the LLM-emitted `file_path` string, runs only `path.exists()` and `path.is_file()`, and dispatches to the appropriate reader. No call to `safe_path` or `safe_user_path` exists in the function. A runtime probe confirmed:\n\n- `read_document(\u0027/etc/passwd\u0027)` returned HTTP 200 with 839 characters of content\n- `read_document(\u0027/etc/shadow\u0027)` returned the full shadow password file\n- `read_document(\u0027/proc/self/environ\u0027)` returned the full process environment, including `OPENROUTER_API_KEY` and `TUSHARE_TOKEN` in plaintext\n\nThis is strictly **wider** than F9: F9 is bounded to `/root` + `/app` via the (overly-broad) envelope; F10 has no envelope at all and reaches `/etc`, `/proc`, `/var`, and any other path the FastAPI process can read.\n\n**Steps to observe**:\n\n1. Per GHSA-1 shared reproducer, start the server with a working LLM API key and create an unauthenticated session.\n2. `curl -s -X POST \"http://HOST:8899/sessions/$SID/messages\" -H \u0027Content-Type: application/json\u0027 -d \u0027{\"content\":\"Please read and summarize the document at /proc/self/environ\"}\u0027`\n3. Poll `curl -s \"http://HOST:8899/sessions/$SID/messages\"`. Observe the agent invoke `read_document` with `file_path=\"/proc/self/environ\"` and return the full process environment in the message stream.\n4. Observe `OPENROUTER_API_KEY`, `TUSHARE_TOKEN`, and any other variables in `agent/.env` appearing in plaintext.\n5. Repeat with `file_path=\"/etc/shadow\"` to confirm shadow password file access.\n\n**Impact**: \nAn unauthenticated caller can retrieve any file the server process can read. Running as root, that includes `/etc/shadow`, `/etc/passwd`, `/proc/self/environ` (full plaintext API keys), `/root/.ssh/id_rsa`, and any secret files mounted into the container. This is the broadest file-read primitive in the codebase and provides a credential-extraction path that does **not** require shell execution \u2014 endpoint monitoring tuned to BashTool / shell signatures will miss it entirely.\n\n---\n\n### Why F9 and F10 are listed separately\n\nA maintainer might be tempted to fix only one, on the theory that F10 dominates F9. Two reasons to fix both:\n\n1. **Different fix scope** \u2014 F10\u0027s fix is a single missing call (`safe_path(file_path)` in `read_document` before line 270). F9\u0027s fix is in `safe_user_path()` itself: the envelope must be replaced with a strict allowlist of operator-configured directories, *not* `Path.home() \u222a Path.cwd()`. A fix that adds the missing `safe_user_path` call to `read_document` is **insufficient** because `safe_user_path` itself accepts `/root` and `/app/agent/.env`. Both surfaces need work.\n\n2. **Different reachability classes** \u2014 F9 is reachable through tools that already gate on `safe_user_path` (`ExtractShadowStrategyTool` and several journal tools), so even a hypothetical F10 fix that switched `read_document` to use `safe_user_path` would still leak `/root/*` because the envelope is broken. F9 is the structural defect; F10 is the missed call.\n\n---\n\n### Suggested remediation\n\n11. **F9** \u2014 In `safe_user_path()` at `path_utils.py:52-77`, replace the `Path.home() \u222a Path.cwd()` envelope with a strict allowlist of operator-configured directories (e.g. an explicit `BROKER_EXPORTS_DIR` env var defaulting to `/app/data/broker_exports/`). Reject `/root`, `/app/agent/.env`, and `/app/agent/uploads/` (the latter to prevent F3-uploaded files from being subsequently parsed as a credential-leak vector via the parse-error channel).\u0027\n\n12. **F10** \u2014 Add a `safe_path()` (or `safe_user_path()`) call at `doc_reader_tool.py:270` before the existing `path.exists()` / `path.is_file()` checks. Once F9 is patched, the same allowlist will apply uniformly to both `read_document` and the `safe_user_path`-gated tools.\n\n13. **Defense-in-depth** \u2014 Drop the FastAPI process to a non-root user. Add a `RUN useradd -m vibe \u0026\u0026 chown -R vibe /app` step to the Dockerfile and `USER vibe` before `CMD`. This does not fix the Path Traversal but materially reduces the credential-extraction blast radius of any successful exploit (and benefits every other finding in GHSA-1 and GHSA-2). See GHSA-1 / shared baseline for the matching `USER` recommendation.\n\n---",
  "id": "GHSA-5rmq-chc7-m22f",
  "modified": "2026-10-02T22:44:12Z",
  "published": "2026-10-02T22:44:12Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/HKUDS/Vibe-Trading/security/advisories/GHSA-5rmq-chc7-m22f"
    },
    {
      "type": "WEB",
      "url": "https://github.com/HKUDS/Vibe-Trading/commit/9454d4a27a763b80e1d6eb5763b86c88e9e4e714"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/HKUDS/Vibe-Trading"
    },
    {
      "type": "WEB",
      "url": "https://github.com/HKUDS/Vibe-Trading/releases/tag/v0.1.7"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Vibe-Trading file-read tools expose arbitrary server-readable files"
}

GHSA-5RQP-847G-V4F2

Vulnerability from github – Published: 2022-12-12 03:31 – Updated: 2025-04-23 15:30
VLAI
Details

The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https://10.10.20.74/lib/. This address has a backup file which can be downloaded without any authentication.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2022-45227"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-552"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2022-12-12T03:15:00Z",
    "severity": "HIGH"
  },
  "details": "The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https://10.10.20.74/lib/. This address has a backup file which can be downloaded without any authentication.",
  "id": "GHSA-5rqp-847g-v4f2",
  "modified": "2025-04-23T15:30:41Z",
  "published": "2022-12-12T03:31:04Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45227"
    },
    {
      "type": "WEB",
      "url": "https://sectrio.com/vulnerability-research/cve-2022-45227"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-5V46-5C9P-J4MG

Vulnerability from github – Published: 2022-05-13 01:34 – Updated: 2022-05-13 01:34
VLAI
Details

redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2018-10869"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-552",
      "CWE-732"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2018-07-19T22:29:00Z",
    "severity": "HIGH"
  },
  "details": "redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.",
  "id": "GHSA-5v46-5c9p-j4mg",
  "modified": "2022-05-13T01:34:56Z",
  "published": "2022-05-13T01:34:56Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10869"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2018:2373"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/security/cve/CVE-2018-10869"
    },
    {
      "type": "WEB",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1593780"
    },
    {
      "type": "WEB",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10869"
    },
    {
      "type": "WEB",
      "url": "http://www.securityfocus.com/bid/105061"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-5VM6-MM87-JJV8

Vulnerability from github – Published: 2022-08-02 00:00 – Updated: 2022-08-05 00:00
VLAI
Details

The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-config.php.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2022-1585"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-552"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2022-08-01T13:15:00Z",
    "severity": "HIGH"
  },
  "details": "The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-config.php.",
  "id": "GHSA-5vm6-mm87-jjv8",
  "modified": "2022-08-05T00:00:24Z",
  "published": "2022-08-02T00:00:27Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1585"
    },
    {
      "type": "WEB",
      "url": "https://wpscan.com/vulnerability/e709958c-7bce-45d7-9a0a-6e0ed12cd03f"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-5W78-C46H-GQXQ

Vulnerability from github – Published: 2023-01-23 15:30 – Updated: 2023-01-30 18:30
VLAI
Details

The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used email address.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2022-4346"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-552"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-01-23T15:15:00Z",
    "severity": "MODERATE"
  },
  "details": "The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used email address.",
  "id": "GHSA-5w78-c46h-gqxq",
  "modified": "2023-01-30T18:30:22Z",
  "published": "2023-01-23T15:30:33Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4346"
    },
    {
      "type": "WEB",
      "url": "https://wpscan.com/vulnerability/cc05f760-983d-4dc1-afbb-6b4965aa8abe"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-5X3H-WQ76-MXQX

Vulnerability from github – Published: 2026-07-28 12:31 – Updated: 2026-07-28 12:31
VLAI
Details

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-11841"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-552"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-07-28T10:16:47Z",
    "severity": "CRITICAL"
  },
  "details": "An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.",
  "id": "GHSA-5x3h-wq76-mxqx",
  "modified": "2026-07-28T12:31:19Z",
  "published": "2026-07-28T12:31:19Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11841"
    },
    {
      "type": "WEB",
      "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices"
    },
    {
      "type": "WEB",
      "url": "https://www.first.org/cvss/calculator/3.1"
    },
    {
      "type": "WEB",
      "url": "https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0010.json"
    },
    {
      "type": "WEB",
      "url": "https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0010.pdf"
    },
    {
      "type": "WEB",
      "url": "https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf"
    },
    {
      "type": "WEB",
      "url": "https://www.sick.com/psirt"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-5X9M-F82G-8667

Vulnerability from github – Published: 2026-09-12 06:31 – Updated: 2026-09-12 18:30
VLAI
Details

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-80494"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-552"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-09-12T06:16:25Z",
    "severity": "HIGH"
  },
  "details": "The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.",
  "id": "GHSA-5x9m-f82g-8667",
  "modified": "2026-09-12T18:30:21Z",
  "published": "2026-09-12T06:31:20Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80494"
    },
    {
      "type": "WEB",
      "url": "https://wpscan.com/vulnerability/fdc0fefb-c090-4972-9867-d1090353e40c"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-64GV-3PQV-299H

Vulnerability from github – Published: 2021-05-07 15:54 – Updated: 2021-05-05 22:31
VLAI
Summary
Exposure of Sensitive Information to an Unauthorized Actor in Apache Wicket
Details

By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Maven",
        "name": "org.apache.wicket:wicket-core"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.17.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Maven",
        "name": "org.apache.wicket:wicket-core"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "8.0.0"
            },
            {
              "fixed": "8.9.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Maven",
        "name": "org.apache.wicket:wicket-core"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "9.0.0-M1"
            },
            {
              "fixed": "9.0.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ],
      "versions": [
        "9.0.0-M1"
      ]
    },
    {
      "package": {
        "ecosystem": "Maven",
        "name": "org.apache.wicket:wicket-core"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "9.0.0-M2"
            },
            {
              "fixed": "9.0.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ],
      "versions": [
        "9.0.0-M2"
      ]
    },
    {
      "package": {
        "ecosystem": "Maven",
        "name": "org.apache.wicket:wicket-core"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "9.0.0-M3"
            },
            {
              "fixed": "9.0.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ],
      "versions": [
        "9.0.0-M3"
      ]
    },
    {
      "package": {
        "ecosystem": "Maven",
        "name": "org.apache.wicket:wicket-core"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "9.0.0-M4"
            },
            {
              "fixed": "9.0.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ],
      "versions": [
        "9.0.0-M4"
      ]
    },
    {
      "package": {
        "ecosystem": "Maven",
        "name": "org.apache.wicket:wicket-core"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "9.0.0-M5"
            },
            {
              "fixed": "9.0.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ],
      "versions": [
        "9.0.0-M5"
      ]
    }
  ],
  "aliases": [
    "CVE-2020-11976"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-200",
      "CWE-552"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2021-05-05T22:31:00Z",
    "nvd_published_at": "2020-08-11T19:15:00Z",
    "severity": "HIGH"
  },
  "details": "By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5",
  "id": "GHSA-64gv-3pqv-299h",
  "modified": "2021-05-05T22:31:00Z",
  "published": "2021-05-07T15:54:15Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-11976"
    },
    {
      "type": "WEB",
      "url": "https://lists.apache.org/thread.html/r05340178680eb6b9d4d40d56b5621dd4ae9715e6f41f12ae2288ec49@%3Cdev.directory.apache.org%3E"
    },
    {
      "type": "WEB",
      "url": "https://lists.apache.org/thread.html/r104eeefeb1e9da51f7ef79cef0f9ff12e21ef8559b77801e86b21e16%40%3Cusers.wicket.apache.org%3E"
    },
    {
      "type": "WEB",
      "url": "https://lists.apache.org/thread.html/r982c626dbce5c995223c4a6ddd7685de3592f8d65ba8372da1f3ce19@%3Cdev.directory.apache.org%3E"
    },
    {
      "type": "WEB",
      "url": "https://lists.apache.org/thread.html/rd0f36b83cc9f28b016ec552f023fb5a59a9ea8db56f2b9dcc6a2f6b7@%3Ccommits.directory.apache.org%3E"
    },
    {
      "type": "WEB",
      "url": "https://lists.apache.org/thread.html/rd26cae6e30b205e09e4b511d3d962d4f677c0c604f737997ce1b2f22@%3Cdev.directory.apache.org%3E"
    },
    {
      "type": "WEB",
      "url": "https://lists.apache.org/thread.html/rdec0a43afdca59c10416889e07267f3d2fdf4ab929a6e22a2659b6ff@%3Cdev.directory.apache.org%3E"
    },
    {
      "type": "WEB",
      "url": "https://lists.apache.org/thread.html/re4af65851bf69605cfb68be215eba36d4cdc1a90b95fbc894799d923@%3Cdev.directory.apache.org%3E"
    },
    {
      "type": "WEB",
      "url": "https://lists.apache.org/thread.html/reb7ea8141c713b5b19eaf34c00f43aaebf5a1c116130f763c42bdad1@%3Cdev.directory.apache.org%3E"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Exposure of Sensitive Information to an Unauthorized Actor in Apache Wicket"
}

Mitigation
Implementation System Configuration Operation

When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to disable public access.

CAPEC-150: Collect Data from Common Resource Locations

An adversary exploits well-known locations for resources for the purposes of undermining the security of the target. In many, if not most systems, files and resources are organized in a default tree structure. This can be useful for adversaries because they often know where to look for resources or files that are necessary for attacks. Even when the precise location of a targeted resource may not be known, naming conventions may indicate a small area of the target machine's file tree where the resources are typically located. For example, configuration files are normally stored in the /etc director on Unix systems. Adversaries can take advantage of this to commit other types of attacks.

CAPEC-639: Probe System Files

An adversary obtains unauthorized information due to improperly protected files. If an application stores sensitive information in a file that is not protected by proper access control, then an adversary can access the file and search for sensitive information.