Skip to main content

Vibe trading ai: Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain

0
Critical
Published: 10/02/2026 (10/02/2026, 22:44:26 UTC)
Source: GCVE Database
Product: vibe-trading-ai

Description

Vibe-Trading AI version 0.1.0 through 0.1.6 contains multiple critical security vulnerabilities, including unauthenticated full API exposure and remote code execution (RCE). The primary critical issue allows unauthenticated attackers to execute arbitrary shell commands as root inside the container via the /sessions/{id}/messages endpoint due to missing authentication enforcement when API_AUTH_KEY is unset. Additional findings include authorization gaps, unauthenticated file uploads, permissive CORS configurations, and partial API key disclosure. The Docker container runs as root by default, increasing the impact of exploitation. A patch is available to address these issues.

CVSS v3.1

Score 10.0critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected software

PyPIghsa
vibe-trading-ai
Affected versions
>=0.1.0 <0.1.7

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/03/2026, 17:40:08 UTC

Technical Analysis

Vibe-Trading AI versions >=0.1.0 and <0.1.7 suffer from multiple security flaws. The most critical is an unauthenticated remote code execution vulnerability (CWE-306 leading to CWE-78) via the POST /sessions/{id}/messages endpoint. This occurs because the require_auth() function returns immediately without enforcing authentication if the API_AUTH_KEY environment variable is unset, making authentication dependencies ineffective. The LLM agent executes shell commands using subprocess.run with shell=True as root inside the container, allowing arbitrary command execution. Additional vulnerabilities include unauthenticated file uploads of executable scripts, overly permissive CORS policies enabling credentialed cross-origin access from localhost ports, and partial API key disclosure via masking functions. The Dockerfile lacks a USER directive, so the FastAPI process runs as root inside the container, exacerbating the risk. The vulnerabilities affect versions from 0.1.0 up to but not including 0.1.7. A patch is available.

Potential Impact

An unauthenticated attacker with network access to port 8899 can execute arbitrary shell commands as root inside the container, resulting in full container compromise. This can lead to complete loss of confidentiality, integrity, and availability of the affected system. Additional vulnerabilities allow unauthorized file uploads and information disclosure, increasing the attack surface. The default root execution context of the container amplifies the severity of the remote code execution.

Mitigation Recommendations

A patch is available for these vulnerabilities. Operators should apply the official fix to ensure authentication is properly enforced and to restrict file uploads and CORS policies. Until patched, do not expose port 8899 to untrusted networks. Configure the Docker container to run the FastAPI process as a non-root user by adding a USER directive in the Dockerfile. Verify that the API_AUTH_KEY environment variable is set to enforce authentication. Review and restrict CORS settings to prevent unauthorized cross-origin requests. Follow the vendor advisory for detailed remediation steps.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-v2f8-6655-7grj
Osv Schema Version
1.4.0
Ecosystems
["PyPI"]
Database Specific Severity
CRITICAL
Cvss Version
3.1

Threat ID: 6ac139aea43b0b3b89d69aec

Added to database: 10/03/2026, 17:21:50 UTC

Last enriched: 10/03/2026, 17:40:08 UTC

Last updated: 10/04/2026, 02:51:32 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses