PatchSiren

SWE-agent CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH SWE-agent CVE published 2026-08-17

CVE-2026-75482

CVE-2026-75482 debrief based on the supplied source corpus. The SWE-agent trajectory inspector, confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassing the built-in path sanitization. An unauthenticated network client can use path traversal sequences to read files outside the int [truncated]