Description
A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src/TraderDD/TraderDD.cpp. The manipulation of the argument FID_JYLB results in enforcement of behavioral workflow. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-07
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the TraderDD::queryTrades function located in src/TraderDD/TraderDD.cpp allows manipulation of the FID_JYLB argument to enforce unintended business logic, effectively permitting unauthorized actions or bypassing controls. The vulnerability is linked to CWE-840 and CWE-841. Attack can be launched remotely, requires high complexity, and is considered difficult to exploit, yet a public exploit is now available. With a CVSS score of 6.3, the issue is classified as moderate severity and could have significant impact on system integrity and business processes.

Affected Systems

WonderTrader WonderTrader versions up to and including 0.9.9 are susceptible to this issue. No other release versions are known to be affected.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate risk to environments hosting the vulnerable product. The EPSS score is not available; the description notes that exploitability is considered difficult, suggesting that widespread attacks are unlikely. The vulnerability is not listed in CISA KEV, yet an active public exploit exists, meaning attackers could potentially leverage it against exposed systems. Remote exploitation would entail invoking the queryTrades API with a crafted FID_JYLB value, so protection can be achieved by restricting network access or monitoring anomalous calls.

Generated by OpenCVE AI on August 7, 2026 at 18:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑issued patch or upgrade to a release newer than 0.9.9 as soon as it is available.
  • Restrict remote access to the TraderDD::queryTrades endpoint using firewall rules or network segmentation so that only trusted clients can invoke the function.
  • Monitor application logs for anomalous queryTrades calls with manipulated FID_JYLB values and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 7, 2026 at 18:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src/TraderDD/TraderDD.cpp. The manipulation of the argument FID_JYLB results in enforcement of behavioral workflow. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title WonderTrader TraderDD.cpp queryTrades behavioral workflow
First Time appeared Wondertrader
Wondertrader wondertrader
Weaknesses CWE-840
CWE-841
CPEs cpe:2.3:a:wondertrader:wondertrader:*:*:*:*:*:*:*:*
Vendors & Products Wondertrader
Wondertrader wondertrader
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wondertrader Wondertrader
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-07T17:08:13.843Z

Reserved: 2026-08-07T08:30:57.200Z

Link: CVE-2026-19208

cve-icon Vulnrichment

Updated: 2026-08-07T17:07:44.025Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T16:17:23.750

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-19208

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T18:30:03Z

Weaknesses