---
id: PYSEC-2026-4009
aliases:
  - GHSA-22mg-8gw7-636x
title: >-
  Path traversal and arbitrary directory deletion/overwrite via agent profile
  import in local-operator
summary: >-
  Path traversal and arbitrary directory deletion/overwrite via agent profile
  import in local-operator
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
vendor: local-operator
product: local-operator
ecosystem: pip
affected:
  - local-operator < 0.47.5
patched:
  - local-operator 0.47.5
published: '2026-09-05'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:46:03.260718926Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2026-4009'
references:
  - url: >-
      https://github.com/damianvtran/local-operator/security/advisories/GHSA-22mg-8gw7-636x
  - url: 'https://github.com/damianvtran/local-operator/pull/643'
  - url: >-
      https://github.com/damianvtran/local-operator/commit/29fc4c68a3ed1d238b8abf6b6a6136a3361416a5
  - url: 'https://github.com/damianvtran/local-operator/releases/tag/v0.47.5'
  - url: 'https://pypi.org/project/local-operator/'
tags:
  - osv
  - pip
ingestedAt: '2026-10-01T07:23:13.169Z'
---

## Overview

The `/v1/agents/import` endpoint and `AgentRegistry.import_agent()` in local-operator versions before 0.47.5 trust the `id` field inside `agent.yml` of an uploaded agent profile archive when constructing the destination directory. A crafted `id` containing directory traversal sequences makes `shutil.rmtree` and `shutil.copy2` operate outside the agent registry, allowing an unauthenticated client with network access to the API to recursively delete arbitrary directories and write files with the privileges of the server process. Even without traversal, an imported archive could overwrite or delete existing local agent profiles.

Version 0.47.5 assigns a fresh server-generated identifier to every imported profile, never derives a filesystem path from archive metadata, creates destination directories exclusively, and binds `lop serve` to 127.0.0.1 by default.



## Affected packages

- `local-operator < 0.47.5`

## Remediation

Upgrade to a patched release:

- `local-operator 0.47.5`
