DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-5RMQ-CHC7-M22F: GHSA-5RMQ-CHC7-M22F: Arbitrary File Read and Path Traversal in Vibe-Trading Platform

GHSA-5RMQ-CHC7-M22F: Arbitrary File Read and Path Traversal in Vibe-Trading Platform

Vulnerability ID: GHSA-5RMQ-CHC7-M22F
CVSS Score: 7.5
Published: 2026-10-02

An arbitrary file read and path traversal vulnerability in the Vibe-Trading platform allows unauthenticated remote attackers to retrieve sensitive configuration files, API keys, and system secrets. The flaw stems from permissive directory checking in path validation tools and a complete lack of input sanitization in the document reader utility. Remediation was introduced in version 0.1.7 by implementing strict path allowlists, forcing user authentication, and dropping root execution privileges within the container environment.

TL;DR

The Vibe-Trading platform before version 0.1.7 exposes arbitrary server-readable files to unauthenticated remote attackers because of loose path validation and unauthenticated API endpoints running with root privileges.


Technical Details

  • CWE ID: CWE-22, CWE-23, CWE-200, CWE-552
  • Attack Vector: Network
  • CVSS Score: 7.5
  • EPSS Score: Not applicable
  • Impact: High Confidentiality Loss
  • Exploit Status: Proof-of-Concept Available
  • KEV Status: Not Listed

Affected Systems

  • Vibe-Trading Platform
  • vibe-trading-ai Python package
  • vibe-trading-ai: >= 0.1.0, < 0.1.7 (Fixed in: 0.1.7)

Code Analysis

Commit: 9454d4a

Harden API and tool security defaults

Mitigation Strategies

  • Upgrade vibe-trading-ai to version 0.1.7 or higher
  • Configure the application process to run as a non-privileged user
  • Apply network access control lists to restrict access to port 8899

Remediation Steps:

  1. Pull the updated source code or update via pip: pip install vibe-trading-ai>=0.1.7
  2. Rebuild the associated Docker containers to adopt the non-root user configuration
  3. Restart the server and verify that session endpoints require authentication

References


Read the full report for GHSA-5RMQ-CHC7-M22F on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)