Advisories for Pypi/Vibe-Trading-Ai package

2026

Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF

5 findings — BashTool shell-injection sink (F6, the canonical RCE primitive), BackgroundRunTool async shell-injection sink (F7), backtest exec_module() runs top-level statements before the SignalEngine class check (F8 — independent RCE path that does not match BashTool signatures), read_url outbound HTTP forwarding without schema/host validation (F-B4 SSRF), and Jinja2 codegen with autoescape disabled for .py.j2 templates (F-B5, defense-in-depth code-injection sink).

Vibe-Trading file-read tools expose arbitrary server-readable files

2 findings — safe_user_path() accepts any path under Path.home() or Path.cwd(), which inside the shipped root container resolves to /root and /app (so all of root's home, including /root/.ssh/id_rsa, /root/.aws/credentials, /root/.kube/config, and /app/agent/.env, passes the check) (F9). read_document() has no sandbox call at all and returns the full content of any path the FastAPI process can read, including /etc/shadow, /etc/passwd, /proc/self/environ, and any secret file mounted into the container (F10). …

Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain

5 findings — unauthenticated full-API exposure (F1, lead Critical), read-side authorization gap that persists even with API_AUTH_KEY set (F2), unauthenticated file write of .py/.sh/.yaml to a server-returned path (F3), default-permissive CORS that combines with a loopback-only check to grant any browser page on whitelisted localhost ports credentialed cross-origin access (F-A4), and partial API-key disclosure via _mask_secret() (F-A5).