Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. vibe-trading-ai
  4. ›
  5. GHSA-5rmq-chc7-m22f

GHSA-5rmq-chc7-m22f: Vibe-Trading file-read tools expose arbitrary server-readable files

October 2, 2026

2 findings — safe_user_path() accepts any path under Path.home() or Path.cwd(), which inside the shipped root container resolves to /root and /app (so all of root’s home, including /root/.ssh/id_rsa, /root/.aws/credentials, /root/.kube/config, and /app/agent/.env, passes the check) (F9). read_document() has no sandbox call at all and returns the full content of any path the FastAPI process can read, including /etc/shadow, /etc/passwd, /proc/self/environ, and any secret file mounted into the container (F10). F10 is strictly broader than F9 but they have different fix scopes (F10 = a missing safe_path() call in one function; F9 = the envelope definition in path_utils.py), so both must be patched.


References

  • github.com/HKUDS/Vibe-Trading/commit/9454d4a27a763b80e1d6eb5763b86c88e9e4e714
  • github.com/HKUDS/Vibe-Trading/releases/tag/v0.1.7
  • github.com/HKUDS/Vibe-Trading/security/advisories/GHSA-5rmq-chc7-m22f
  • github.com/advisories/GHSA-5rmq-chc7-m22f

Code Behaviors & Features

Detect and mitigate GHSA-5rmq-chc7-m22f with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 0.1.0 before 0.1.7

Fixed versions

  • 0.1.7

Solution

Upgrade to version 0.1.7 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • CWE-23: Relative Path Traversal
  • CWE-552: Files or Directories Accessible to External Parties

Source file

pypi/vibe-trading-ai/GHSA-5rmq-chc7-m22f.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 03 Oct 2026 12:17:25 +0000.