Impact
A logic error in the selfRegister API endpoint of HKUDS AI‑Trader allows an attacker to manipulate the initial_balance argument. This flaw is a broken business logic vulnerability (CWE‑840). By sending an inflated initial_balance, a remote user can increase the amount displayed in the equity column and skew leaderboard rankings. The underlying financial calculations remain correct, so no real monetary advantage is gained beyond a cosmetic presentation.
Affected Systems
The vulnerability affects HKUDS AI‑Trader, a continuously delivered platform with rolling releases. Because the product updates frequently and no specific release is identified, any version released before a vendor patch that addresses the logic check in routes_agent.py is potentially impacted. No explicit affected‑version list is available.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, while the EPSS score is not provided and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit this flaw remotely, but it requires high complexity and is considered difficult to execute. The primary impact is the ability to distort leaderboard displays, which may undermine trust and fairness in the simulated trading environment.
OpenCVE Enrichment