{"data":{"id":"2a21c632-f3d4-4d2d-ab62-b2240e1fb5d7","title":"GHSA-jqmf-mx4f-hfr6: Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF","summary":"Vibe-Trading's LLM-callable tools contain five critical vulnerabilities that allow remote code execution and data exfiltration. The main issue is that BashTool passes commands from the LLM directly to the operating system without any filtering, and all five tools are automatically available to the LLM agent by default with no authentication required. Additionally, attackers can inject malicious instructions into documents that the LLM processes, tricking it into executing harmful commands.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-jqmf-mx4f-hfr6","publishedAt":"2026-10-02T22:44:03.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":"critical","severity":"critical","attackType":["prompt_injection"],"issueType":"vulnerability","affectedPackages":["vibe-trading-ai@>= 0.1.0, < 0.1.7 (fixed: 0.1.7)"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["Vibe-Trading","OpenRouter"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":true,"disclosureDate":"2026-10-02T22:44:03.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}