HighVulnerabilityLLM-specific
GHSA-5rmq-chc7-m22f: Vibe-Trading file-read tools expose arbitrary server-readable files
- Identifier
- GHSA-5rmq-chc7-m22f
- Published
- Record updated
Summary
GHSA-5rmq-chc7-m22f affects the Vibe-Trading file-read tools. The safe_user_path() check in agent/src/tools/path_utils.py accepts any path under Path.home() or Path.cwd(), which resolve to /root and /app inside the shipped container, so files such as /root/.ssh/id_rsa and /app/agent/.env pass. read_document() performs no sandbox check and returns any file the FastAPI process, running as root, can read, and the advisory reports that unauthenticated clients can reach it on port 8899.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database