Openbmb's vulnerability profile centers on xAgent, a specialized agent framework product, with observed disclosures clustering around authentication, authorization, and information-disclosure weaknesses including user-controlled key handling, path traversal, and credential management flaws. These patterns reflect the access-control and data-boundary challenges common to agent-oriented architectures. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openbmb over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2007HIGH A vulnerability was found in OpenBMB XAgent 1.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Privileged Mode. Th | Mar 21, 2024 | 8.8 | 28 | NO | NO |
CVE-2026-4959HIGH A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/application/websockets/share.py of the component ShareServer WebSoc | Mar 27, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-4958MEDIUM A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.send_data of the file XAgentServer/application/websockets/rep | Mar 27, 2026 | 6.5 | 22 | NO | NO |
CVE-2025-6281MEDIUM A vulnerability has been found in OpenBMB XAgent up to 1.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /conv/community. The | Jun 19, 2025 | 6.3 | 18 | NO | NO |
A flaw has been found in OpenBMB XAgent 1.0.0. The impacted element is the function FunctionHandler.handle_tool_call of the file XAgent/function_handler.py of the component API Key | Mar 27, 2026 | 2.7 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openbmb.
Media articles that mention a CVE ID that affects a product developed by Openbmb — matched by CVE ID, not by vendor name.