Back

HIGH

SWE-agent Trajectory Inspector Path Traversal File Disclosure

Published Aug 17, 2026

Description

SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassing the built-in path sanitization. The server binds all interfaces (0.0.0.0), applies wildcard CORS, and requires no authentication. An unauthenticated network client (or a malicious web page via CORS) can use path traversal sequences to read files outside the intended directory. Because the read sink parses targets as trajectory JSON, disclosure is constrained to JSON files shaped like a trajectory, which can contain repository contents, command output, and secrets/API keys.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 17, 2026
Updated Sep 24, 2026
Reserved Aug 17, 2026
CISA Vulnrichment
Updated Aug 18, 2026
NVD
Status Received
Modified Aug 18, 2026
Red Hat
Severity n/a
Public date n/a