GHSA-5RMQ-CHC7-M22F: Arbitrary File Read and Path Traversal in Vibe-Trading Platform
Vulnerability ID: GHSA-5RMQ-CHC7-M22F
CVSS Score: 7.5
Published: 2026-10-02
An arbitrary file read and path traversal vulnerability in the Vibe-Trading platform allows unauthenticated remote attackers to retrieve sensitive configuration files, API keys, and system secrets. The flaw stems from permissive directory checking in path validation tools and a complete lack of input sanitization in the document reader utility. Remediation was introduced in version 0.1.7 by implementing strict path allowlists, forcing user authentication, and dropping root execution privileges within the container environment.
TL;DR
The Vibe-Trading platform before version 0.1.7 exposes arbitrary server-readable files to unauthenticated remote attackers because of loose path validation and unauthenticated API endpoints running with root privileges.
Technical Details
- CWE ID: CWE-22, CWE-23, CWE-200, CWE-552
- Attack Vector: Network
- CVSS Score: 7.5
- EPSS Score: Not applicable
- Impact: High Confidentiality Loss
- Exploit Status: Proof-of-Concept Available
- KEV Status: Not Listed
Affected Systems
- Vibe-Trading Platform
- vibe-trading-ai Python package
-
vibe-trading-ai: >= 0.1.0, < 0.1.7 (Fixed in:
0.1.7)
Code Analysis
Commit: 9454d4a
Harden API and tool security defaults
Mitigation Strategies
- Upgrade vibe-trading-ai to version 0.1.7 or higher
- Configure the application process to run as a non-privileged user
- Apply network access control lists to restrict access to port 8899
Remediation Steps:
- Pull the updated source code or update via pip: pip install vibe-trading-ai>=0.1.7
- Rebuild the associated Docker containers to adopt the non-root user configuration
- Restart the server and verify that session endpoints require authentication
References
Read the full report for GHSA-5RMQ-CHC7-M22F on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)