GHSA-JQMF-MX4F-HFR6: Multiple Remote Code Execution and Security Flaws in Vibe-Trading AI-Agent Pipeline
Vulnerability ID: GHSA-JQMF-MX4F-HFR6
CVSS Score: 10.0
Published: 2026-10-02
An in-depth technical analysis of multiple critical security flaws identified in the Vibe-Trading ecosystem (vibe-trading-ai). These issues range from unauthenticated remote command injection via agent tool executions to arbitrary Python execution through dynamic module loading and unsafe Jinja2 template autoescaping, allowing full system compromise.
TL;DR
Unauthenticated remote attackers can execute arbitrary OS commands and Python scripts as root via vulnerable AI-agent tool workflows, backtest runner dynamics, and SSRF points in Vibe-Trading < 0.1.7.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-78, CWE-94, CWE-918
- Attack Vector: Network / Unauthenticated API Request
- CVSS v3.1: 10.0 (Critical)
- CVSS v4.0: 9.3 (Critical)
- Exploit Status: Proof-of-Concept (PoC) Publicly Available
- Impact: Remote Code Execution (RCE) / Full System Compromise
- Root Cause: Direct shell execution, unsafe dynamic imports, and lack of authentication defaults
Affected Systems
- Vibe-Trading API service
- vibe-trading-ai python package
- Vibe-Trading backtest execution environment
-
vibe-trading-ai: >= 0.1.0, < 0.1.7 (Fixed in:
0.1.7)
Code Analysis
Commit: 9454d4a
Implement core API authentication, opt-in policies for shell tools, path traversal checks, and AST structural verification of dynamic python script modules.
Exploit Details
- GitHub Security Advisory Details: Functional PoC scenarios demonstrating command injection, backtest runner execution, and Jinja2 path issues.
Mitigation Strategies
- Disable powerful shell utilities by ensuring VIBE_TRADING_ENABLE_SHELL_TOOLS is not set to 1.
- Enforce API token authentication policies using unique API keys verified via hmac.compare_digest.
- Perform static analysis of all LLM-generated modules with Python's ast framework before dynamic loading.
Remediation Steps:
- Upgrade the python package vibe-trading-ai to version 0.1.7 or higher.
- Implement the non-privileged service user 'vibe' in Dockerfile configurations.
- Map API ports only to 127.0.0.1 within docker-compose.yml files.
References
Read the full report for GHSA-JQMF-MX4F-HFR6 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)