No published models are known to use this package.
cvss
0.0
critical
severity band, no base score published
epss
not scored
chance of exploitation in 30 days
xyz score
0.0
medium
CyberXYZ composite out of 10
fig. 01 — GHSA-22mg-8gw7-636x, the advisory selected below
// 2 advisories
GHSA-22mg-8gw7-636x
CRITICAL
The /v1/agents/import endpoint and AgentRegistry.importagent() in local-operator versions before 0.47.5 trust the id field inside agent.yml of an uploaded agent profile archive when constructing the destination directory. A crafted id containing directory traversal sequences makes shutil.rmtree and shutil.copy2 operate outside the agent registry, allowing an unauthenticated client with network access to the API to recursively delete arbitrary directories and write files with the privileges of the server process. Even without traversal, an imported archive could overwrite or delete existing local agent profiles.
Version 0.47.5 assigns a fresh server-generated identifier to every imported profile, never derives a filesystem path from archive metadata, creates destination directories exclusively, and binds lop serve to 127.0.0.1 by default.
Checked 2026-10-01 at 23:56 UTC. The most recent advisory here was published 2026-09-05. Updated continuously from NVD, GHSA, OSV and CNA feeds.