my.feishu.cnexploit
https://my.feishu.cn/wiki/BMjWwb5c3iEkgIkwi3wcOAKjnpc CVE-2026-19208
MEDIUM
WonderTrader TraderDD.cpp queryTrades behavioral workflow
Record summary
CVE-2026-19208 has a selected CVSS score of 6.3 (medium).
Description
A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src/TraderDD/TraderDD.cpp. The manipulation of the argument FID_JYLB results in enforcement of behavioral workflow. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 7, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WonderTrader | CVE List | 0.9.0 | affected |
| 0.9.1 | affected | ||
| 0.9.2 | affected | ||
| 0.9.3 | affected | ||
| 0.9.4 | affected | ||
| 0.9.5 | affected | ||
| 0.9.6 | affected | ||
| 0.9.7 | affected | ||
| 0.9.8 | affected | ||
| 0.9.9 | affected |
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-19208 CVE-2026-19208 | CVE Analysis and ReportThird-party advisory
https://vuldb.com/cve/CVE-2026-19208 Submit #864856 | GitHub wondertrader 0.9.9 Incorrect ComparisonThird-party advisory
https://vuldb.com/submit/864856 VDB-386953 | WonderTrader TraderDD.cpp queryTrades behavioral workflowvdb entryTechnical description
https://vuldb.com/vuln/386953 VDB-386953 | CTI Indicators (IOB, IOC, IOA)signaturepermissions required
https://vuldb.com/vuln/386953/cti