{"data":{"id":"912debe5-b019-41bd-95a6-497b41386c89","title":"GHSA-5rmq-chc7-m22f: Vibe-Trading file-read tools expose arbitrary server-readable files","summary":"GHSA-5rmq-chc7-m22f affects the Vibe-Trading file-read tools. The safe_user_path() check in agent/src/tools/path_utils.py accepts any path under Path.home() or Path.cwd(), which resolve to /root and /app inside the shipped container, so files such as /root/.ssh/id_rsa and /app/agent/.env pass. read_document() performs no sandbox check and returns any file the FastAPI process, running as root, can read, and the advisory reports that unauthenticated clients can reach it on port 8899.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-5rmq-chc7-m22f","publishedAt":"2026-10-02T22:44:12.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["vibe-trading-ai@>= 0.1.0, < 0.1.7 (fixed: 0.1.7)"],"affectedPackageNames":["vibe-trading-ai"],"affectedVendors":[],"affectedVendorsRaw":["Vibe-Trading"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":["GHSA-5rmq-chc7-m22f"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-02T22:44:12.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}