LOW🇵🇱 Wersja polska

CVE-2026-4958

CVSS 1.3v4.0pub. 2026-03-27upd. 2026-04-29

A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.send_data of the file XAgentServer/application/websockets/replayer.py of the component WebSocket Endpoint. Such manipulation of the argument interaction_id leads to authorization bypass. The attack may be launched remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Openbmb Xagent

    APP
    Openbmb
    1.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-4959MEDIUM5.5same product

W OpenBMB XAgent 1.0.0 odkryto podatność wpływającą na funkcję check_user w pliku XAgentServer/application/web...

CVE-2024-2007MEDIUM5.3same product

A vulnerability was found in OpenBMB XAgent 1.0.0. It has been declared as critical. Affected by this vulnerab...

CVE-2026-4957LOW2.0same product

W OpenBMB XAgent 1.0.0 znaleziono lukę. Problem dotyczy funkcji FunctionHandler.handle_tool_call w pliku XAgen...

CVE-2025-6281LOW2.0same product

W OpenBMB XAgent do wersji 1.0.0 odkryto krytyczną lukę bezpieczeństwa dotyczącą nieznanej funkcjonalności pli...