Vendor
The SWE-agent trajectory inspector version 1.1.0 is vulnerable to unauthenticated path traversal via the /trajectory/ handler, allowing attackers to read JSON-formatted sensitive files.