local-operator vulnerabilities
CVEs whose affected-version data names the local-operator package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
PYSEC-2026-4010High· 7.5Arbitrary file read via workspace confinement bypass in local-operator /v1/chat/agents/{id}/edit
Arbitrary file read via workspace confinement bypass in local-operator /v1/chat/agents/{id}/edit
▾ Twilightlocal-operator · local-operatorvia OSV
PYSEC-2026-4009Critical· 9.1Path traversal and arbitrary directory deletion/overwrite via agent profile import in local-operator
Path traversal and arbitrary directory deletion/overwrite via agent profile import in local-operator
▾ Midnightlocal-operator · local-operatorvia OSV