A vulnerability has been found in OpenBMB XAgent and classified as problematic. This vulnerability affects unknown code of the file /workspace/file of the component Workspace File Endpoint. The manipulation of the argument file_name leads to path traversal.
This vulnerability is documented as CVE-2026-72713. The attack can be initiated remotely. There is not any exploit available.
It is recommended to apply a patch to fix this issue.