Xagent
This hub aggregates every CVE we track for Xagent, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
8
CVEs tracked
0
Critical
2
High
0
In CISA KEV
Severity distribution
MEDIUM4LOW2HIGH2
Monthly trend
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
4
0
0
0
0
1
2024-092026-08
Latest CVEs
The 8 most recently published vulnerabilities affecting Xagent.
- CVE-2026-72713XAgent Path Traversal Arbitrary File Read via /workspace/file7.5
- CVE-2026-4959OpenBMB XAgent ShareServer WebSocket Endpoint share.py check_user missing authentication7.3
- CVE-2026-4958OpenBMB XAgent WebSocket Endpoint replayer.py ReplayServer.send_data authorization3.1
- CVE-2026-4957OpenBMB XAgent API Key function_handler.py FunctionHandler.handle_tool_call log file2.7
- CVE-2026-3954OpenBMB XAgent workspace.py workspace path traversal6.5
- CVE-2025-6281OpenBMB XAgent community path traversal5.5
- CVE-2024-2007OpenBMB XAgent Privileged Mode sandbox5.3
- CVE-2022-4326Trellix xAgent permission bypass vulnerability5.5
Product normalization is registry-driven with AI assist and human review. How it works