Threat

Vibe-Trading AI Agent Unauthenticated RCE: Upgrade Now

Page published

Earliest dated coverage: 3 Oct 2026 · First observed: 7 Oct 2026 · Latest dated coverage: 3 Oct 2026

Coverage timeline

3 Oct 2026threatfrontier.com

Single-source advisory — one report is available.

Why it matters

Vibe-Trading exposes an LLM agent with shell and code-execution tools over an unauthenticated API alongside live brokerage, market-data, LLM and cloud credentials, so any exposed instance on a widely starred project can hand an attacker root and a wallet's worth of keys.

Three GitHub-reviewed advisories for HKUDS Vibe-Trading, an open-source LLM trading agent, describe how an unauthenticated network client could chain an open FastAPI endpoint (port 8899), unauthenticated file upload, and LLM-callable shell/code-execution tools into a root shell on a default Docker deployment, plus SSRF and arbitrary file-read, exposing plaintext broker, LLM and cloud keys from the .env file. The flaws (GHSA-v2f8-6655-7grj, GHSA-jqmf-mx4f-hfr6, GHSA-5rmq-chc7-m22f, CVSS up to 10.0) are fixed in 0.1.7; four later CVEs (CVE-2026-58169/58170/58171/58173) affect releases before 0.1.10, with 0.1.16 the current supported release. No exploitation has been reported.