CVE Browser
CVE-2026-72713 HIGH
XAgent Path Traversal Arbitrary File Read via /workspace/file
CVSS 8.7 EPSS 0.83% Aug 11, 2026
CVE-2026-58166 HIGH
OpenBMB ChatDev - Unauthenticated Path Traversal in Upload Handler Allows Arbitrary File Write and Delete
CVSS 8.8 EPSS 0.85% Jun 30, 2026
CVE-2026-4959 MEDIUM
OpenBMB XAgent ShareServer WebSocket Endpoint share.py check_user missing authentication
CVSS 6.9 EPSS 0.76% Mar 27, 2026
CVE-2026-4958 LOW
OpenBMB XAgent WebSocket Endpoint replayer.py ReplayServer.send_data authorization
CVSS 2.3 EPSS 0.51% Mar 27, 2026
CVE-2026-4957 MEDIUM
OpenBMB XAgent API Key function_handler.py FunctionHandler.handle_tool_call log file
CVSS 5.1 EPSS 0.48% Mar 27, 2026
CVE-2026-3954 MEDIUM
OpenBMB XAgent workspace.py workspace path traversal
CVSS 6.9 EPSS 0.68% Mar 11, 2026
CVE-2025-6281 MEDIUM
OpenBMB XAgent community path traversal
CVSS 5.1 EPSS 0.52% Jun 19, 2025
CVE-2024-2007 HIGH
OpenBMB XAgent Privileged Mode sandbox
CVSS 8.8 EPSS 0.28% Feb 29, 2024
Showing 1 to 8 CVEs · page 1