---
id: PYSEC-2026-4010
aliases:
  - GHSA-3xjw-9qpc-53mh
title: >-
  Arbitrary file read via workspace confinement bypass in local-operator
  /v1/chat/agents/{id}/edit
summary: >-
  Arbitrary file read via workspace confinement bypass in local-operator
  /v1/chat/agents/{id}/edit
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
vendor: local-operator
product: local-operator
ecosystem: pip
affected:
  - local-operator < 0.47.5
patched:
  - local-operator 0.47.5
published: '2026-09-05'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:46:03.260834528Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2026-4010'
references:
  - url: >-
      https://github.com/damianvtran/local-operator/security/advisories/GHSA-3xjw-9qpc-53mh
  - url: 'https://github.com/damianvtran/local-operator/pull/643'
  - url: >-
      https://github.com/damianvtran/local-operator/commit/29fc4c68a3ed1d238b8abf6b6a6136a3361416a5
  - url: 'https://github.com/damianvtran/local-operator/releases/tag/v0.47.5'
  - url: 'https://pypi.org/project/local-operator/'
tags:
  - osv
  - pip
ingestedAt: '2026-10-01T07:23:13.170Z'
---

## Overview

The `/v1/chat/agents/{agent_id}/edit` endpoint in local-operator versions before 0.47.5 resolves the caller-supplied `file_path` with `expanduser().resolve()` and reads it without checking that it lies inside the agent's workspace. An unauthenticated client with network access to the API can supply an absolute path or a path containing traversal sequences and obtain the contents of any file readable by the server process, which are placed in the model prompt and returned in the response.

Version 0.47.5 resolves server-side reads within the agent's configured workspace and rejects canonical paths outside it (including symlink and junction escapes) before any model call, adds an optional `file_content` request field so clients can submit a buffer without host path resolution, and binds `lop serve` to 127.0.0.1 by default.



## Affected packages

- `local-operator < 0.47.5`

## Remediation

Upgrade to a patched release:

- `local-operator 0.47.5`
