important · Edge / RCE
Vibe-Trading's default API composes with its shell tools into unauthenticated root execution inside the container.
Affects
Vibe-Trading, a self-hosted LLM trading agent and FastAPI service commonly deployed in a Linux container.
Leaving API_AUTH_KEY unset disables authentication on the documented port 8899 deployment.
Detail and 3 sources
A caller can then control an agent session and reach shell or dynamic-module tools running as uid 0.
The project advisories include HTTP reproduction steps and a runtime uid-0 probe.
Sources
Code / PoCUnauthenticated network clients can drive the entire FastAPI surface (RCE entry, session-history read, arbitrary file write, partial API-key disclosure, browser-mediated cross-origin entry) · Advisory · HKUDS/Vibe-Trading · GitHubCode / PoCLLM-callable tool primitives execute attacker-controlled commands, code, and outbound URLs without input validation (BashTool / BackgroundRunTool shell=True, backtest exec_module premature exec, read_url SSRF, codegen autoescape gap) · Advisory · HKUDS/Vibe-Trading · GitHubVendorVibe-Trading AI Agent Unauthenticated RCE: Upgrade Now