Threat
Vibe-Trading AI Agent Unauthenticated RCE: Upgrade Now
First reported · Discovered threatfrontier.com
Page published
Earliest dated coverage: 3 Oct 2026 · First observed: 7 Oct 2026 · Latest dated coverage: 3 Oct 2026
Coverage timeline
Single-source advisory — one report is available.
Why it matters
Vibe-Trading exposes an LLM agent with shell and code-execution tools over an unauthenticated API alongside live brokerage, market-data, LLM and cloud credentials, so any exposed instance on a widely starred project can hand an attacker root and a wallet's worth of keys.
Three GitHub-reviewed advisories for HKUDS Vibe-Trading, an open-source LLM trading agent, describe how an unauthenticated network client could chain an open FastAPI endpoint (port 8899), unauthenticated file upload, and LLM-callable shell/code-execution tools into a root shell on a default Docker deployment, plus SSRF and arbitrary file-read, exposing plaintext broker, LLM and cloud keys from the .env file. The flaws (GHSA-v2f8-6655-7grj, GHSA-jqmf-mx4f-hfr6, GHSA-5rmq-chc7-m22f, CVSS up to 10.0) are fixed in 0.1.7; four later CVEs (CVE-2026-58169/58170/58171/58173) affect releases before 0.1.10, with 0.1.16 the current supported release. No exploitation has been reported.