GHSA-v2f8-6655-7grj: Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
Summary
Vibe-Trading's FastAPI server has five security flaws that allow attackers to execute commands as root without authentication. The main issue is that the authentication key (`API_AUTH_KEY`) is commented out by default, causing the `require_auth()` function to return immediately without checking credentials, leaving all endpoints unprotected. Additionally, the FastAPI process runs as root (uid=0) inside the container, and the server listens on all network interfaces (0.0.0.0:8899), so any remote attacker can send commands to the LLM agent, which will execute them as shell commands with root privileges.
Classification
Affected Vendors
Affected Packages
Related Issues
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
CVE-2024-27444: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-
Original source: https://github.com/advisories/GHSA-v2f8-6655-7grj
First tracked: October 2, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%