Description
A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215. This affects an unknown part of the file /api/research/agents.csv of the component Research Export. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The patch is named 91a31aac1b0f4dbc6b8bef9f6eff0b7912e0bc65. Applying a patch is the recommended action to fix this issue. The vendor confirms: "Research export endpoints now require an authenticated agent with the research_exports capability".
Problem types
Product status
Timeline
| 2026-06-14: | Advisory disclosed |
| 2026-06-14: | VulDB entry created |
| 2026-06-14: | VulDB entry last update |
Credits
davidgilmore (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/370846 (VDB-370846 | HKUDS AI-Trader Research Export agents.csv information disclosure)
vuldb.com/vuln/370846/cti (VDB-370846 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-12203 (CVE-2026-12203 | CVE Analysis and Report)
vuldb.com/submit/830273 (Submit #830273 | HKUDS AI-Trader 1.0 Information Disclosure)
github.com/HKUDS/AI-Trader/issues/242
github.com/HKUDS/AI-Trader/pull/227
github.com/...a Exposure in Research Export (CVE-Pending).md
github.com/...ommit/91a31aac1b0f4dbc6b8bef9f6eff0b7912e0bc65
github.com/HKUDS/AI-Trader/