CVE-2026-12203: HKUDS AI-Trader Research Export agents.csv information disclosure
A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215. This affects an unknown part of the file /api/research/agents.csv of the component Research Export. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The patch is named 91a31aac1b0f4dbc6b8bef9f6eff0b7912e0bc65. Applying a patch is the recommended action to fix this issue. The vendor confirms: "Research export endpoints now require an authenticated agent with the researchexports capability".
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HKUDS AI-Traderto a version that resolves this vulnerability.Patch 91a31aac1b0f4dbc6b8bef9f6eff0b7912e0bc65 - Configuration
Update the Research Export service so that the /api/research/agents.csv research export endpoint requires an authenticated agent possessing the research_exports capability.
Research Export Authentication requirement for /api/research/agents.csv (research export endpoints) = Authenticated agent with research_exports capability required
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12203?
The severity of CVE-2026-12203 is rated as medium with a score of 5.3.
How does CVE-2026-12203 affect HKUDS AI-Trader?
CVE-2026-12203 affects the Research Export component, allowing for an information disclosure through manipulation of the /api/research/agents.csv file.
Is remote exploitation possible with CVE-2026-12203?
Yes, remote exploitation of CVE-2026-12203 is possible.
What type of vulnerability is CVE-2026-12203 classified as?
CVE-2026-12203 is classified as an information leakage vulnerability (CWE-200).
What impact does CVE-2026-12203 have on data confidentiality?
CVE-2026-12203 potentially compromises data confidentiality by disclosing sensitive information in a CSV file.