{"data":{"id":"9d080f59-c2b9-4a10-9f0b-3f4bb1bb38aa","title":"GHSA-v2f8-6655-7grj: Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain","summary":"Vibe-Trading's FastAPI server has five security flaws that allow attackers to execute commands as root without authentication. The main issue is that the authentication key (`API_AUTH_KEY`) is commented out by default, causing the `require_auth()` function to return immediately without checking credentials, leaving all endpoints unprotected. Additionally, the FastAPI process runs as root (uid=0) inside the container, and the server listens on all network interfaces (0.0.0.0:8899), so any remote attacker can send commands to the LLM agent, which will execute them as shell commands with root privileges.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-v2f8-6655-7grj","publishedAt":"2026-10-02T22:44:26.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":"critical","severity":"critical","attackType":["prompt_injection"],"issueType":"vulnerability","affectedPackages":["vibe-trading-ai@>= 0.1.0, < 0.1.7 (fixed: 0.1.7)"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["Vibe-Trading","FastAPI","OpenRouter"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":true,"disclosureDate":"2026-10-02T22:44:26.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}