Vibe trading ai: Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
Vibe-Trading AI version 0.1.0 through 0.1.6 contains multiple critical security vulnerabilities, including unauthenticated full API exposure and remote code execution (RCE). The primary critical issue allows unauthenticated attackers to execute arbitrary shell commands as root inside the container via the /sessions/{id}/messages endpoint due to missing authentication enforcement when API_AUTH_KEY is unset. Additional findings include authorization gaps, unauthenticated file uploads, permissive CORS configurations, and partial API key disclosure. The Docker container runs as root by default, increasing the impact of exploitation. A patch is available to address these issues.
AI Analysis
Technical Summary
Vibe-Trading AI versions >=0.1.0 and <0.1.7 suffer from multiple security flaws. The most critical is an unauthenticated remote code execution vulnerability (CWE-306 leading to CWE-78) via the POST /sessions/{id}/messages endpoint. This occurs because the require_auth() function returns immediately without enforcing authentication if the API_AUTH_KEY environment variable is unset, making authentication dependencies ineffective. The LLM agent executes shell commands using subprocess.run with shell=True as root inside the container, allowing arbitrary command execution. Additional vulnerabilities include unauthenticated file uploads of executable scripts, overly permissive CORS policies enabling credentialed cross-origin access from localhost ports, and partial API key disclosure via masking functions. The Dockerfile lacks a USER directive, so the FastAPI process runs as root inside the container, exacerbating the risk. The vulnerabilities affect versions from 0.1.0 up to but not including 0.1.7. A patch is available.
Potential Impact
An unauthenticated attacker with network access to port 8899 can execute arbitrary shell commands as root inside the container, resulting in full container compromise. This can lead to complete loss of confidentiality, integrity, and availability of the affected system. Additional vulnerabilities allow unauthorized file uploads and information disclosure, increasing the attack surface. The default root execution context of the container amplifies the severity of the remote code execution.
Mitigation Recommendations
A patch is available for these vulnerabilities. Operators should apply the official fix to ensure authentication is properly enforced and to restrict file uploads and CORS policies. Until patched, do not expose port 8899 to untrusted networks. Configure the Docker container to run the FastAPI process as a non-root user by adding a USER directive in the Dockerfile. Verify that the API_AUTH_KEY environment variable is set to enforce authentication. Review and restrict CORS settings to prevent unauthorized cross-origin requests. Follow the vendor advisory for detailed remediation steps.
Vibe trading ai: Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
Description
Vibe-Trading AI version 0.1.0 through 0.1.6 contains multiple critical security vulnerabilities, including unauthenticated full API exposure and remote code execution (RCE). The primary critical issue allows unauthenticated attackers to execute arbitrary shell commands as root inside the container via the /sessions/{id}/messages endpoint due to missing authentication enforcement when API_AUTH_KEY is unset. Additional findings include authorization gaps, unauthenticated file uploads, permissive CORS configurations, and partial API key disclosure. The Docker container runs as root by default, increasing the impact of exploitation. A patch is available to address these issues.
CVSS v3.1
Score 10.0critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Vibe-Trading AI versions >=0.1.0 and <0.1.7 suffer from multiple security flaws. The most critical is an unauthenticated remote code execution vulnerability (CWE-306 leading to CWE-78) via the POST /sessions/{id}/messages endpoint. This occurs because the require_auth() function returns immediately without enforcing authentication if the API_AUTH_KEY environment variable is unset, making authentication dependencies ineffective. The LLM agent executes shell commands using subprocess.run with shell=True as root inside the container, allowing arbitrary command execution. Additional vulnerabilities include unauthenticated file uploads of executable scripts, overly permissive CORS policies enabling credentialed cross-origin access from localhost ports, and partial API key disclosure via masking functions. The Dockerfile lacks a USER directive, so the FastAPI process runs as root inside the container, exacerbating the risk. The vulnerabilities affect versions from 0.1.0 up to but not including 0.1.7. A patch is available.
Potential Impact
An unauthenticated attacker with network access to port 8899 can execute arbitrary shell commands as root inside the container, resulting in full container compromise. This can lead to complete loss of confidentiality, integrity, and availability of the affected system. Additional vulnerabilities allow unauthorized file uploads and information disclosure, increasing the attack surface. The default root execution context of the container amplifies the severity of the remote code execution.
Mitigation Recommendations
A patch is available for these vulnerabilities. Operators should apply the official fix to ensure authentication is properly enforced and to restrict file uploads and CORS policies. Until patched, do not expose port 8899 to untrusted networks. Configure the Docker container to run the FastAPI process as a non-root user by adding a USER directive in the Dockerfile. Verify that the API_AUTH_KEY environment variable is set to enforce authentication. Review and restrict CORS settings to prevent unauthorized cross-origin requests. Follow the vendor advisory for detailed remediation steps.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-v2f8-6655-7grj
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6ac139aea43b0b3b89d69aec
Added to database: 10/03/2026, 17:21:50 UTC
Last enriched: 10/03/2026, 17:40:08 UTC
Last updated: 10/04/2026, 02:51:32 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.