{"id":"CVE-2026-58173","summary":"Vibe-Trading \u003c 0.1.10 - Path Traversal via Persistent Memory Type","details":"Vibe-Trading before 0.1.10 contains a path traversal vulnerability that allows attackers to write files outside the intended memory root directory by supplying a malicious memory_type value containing path traversal sequences through the remember tool. Attackers can manipulate the memory_type parameter in the persistent memory store to cause the application to write arbitrary Markdown files to unintended locations on the filesystem.","modified":"2026-07-16T03:31:11.464868112Z","published":"2026-06-30T15:55:29.117Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58173.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58173.json"},{"type":"ADVISORY","url":"https://github.com/HKUDS/Vibe-Trading/releases/tag/v0.1.10"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58173"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/vibe-trading-path-traversal-via-persistent-memory-type"},{"type":"REPORT","url":"https://github.com/HKUDS/Vibe-Trading/pull/257"},{"type":"PACKAGE","url":"https://github.com/HKUDS/Vibe-Trading"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hkuds/vibe-trading","events":[{"introduced":"0"},{"fixed":"54f944743efee7b9cbaaeafb5966c583d0d4ac66"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"0.1.10"}]}}],"versions":["v0.1.9","v0.1.8","v0.1.7","v0.1.6","v0.1.5","v0.1.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58173.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}