criticalCVSS 10Vulnerability

GHSA-v2f8-6655-7grj

### Summary: 5 findings — unauthenticated full-API exposure (F1, lead Critical), read-side authorization gap that persists even with `API_AUTH_KEY` set (F2), unauthenticated file write of `.py`/`.sh`/`.yaml` to a server-returned path (F3), default-permissive CORS that combines with a loopback-only check to grant any browser page on whitelisted localhost ports credentialed cross-origin access (F-A4), and partial API-key disclosure via `_mask_secret()` (F-A5). --- ### Shared baseline (applies to all 5 findings) The shipped `agent/.env.example` line 112 ships `# API_AUTH_KEY=` commented out. `require_auth()` at `agent/api_server.py` line 303 executes `if not api_key: return` and returns `None` immediately when `API_AUTH_KEY` is unset, so every endpoint decorated with `dependencies=[Depends(require_auth)]` operates as unauthenticated. The shipped `Dockerfile` does **not** contain a `USER` directive, so the FastAPI process runs as `uid=0(root)` inside the container (verified: `docker exec id` returns `uid=0(root) gid=0(root)`). The `docker-compose.yml` binds `0.0.0.0:8899` with no network restriction. The only operator action required beyond a clean install is supplying a working LLM API key so the agent loop can complete its tool-call round trip — this is the normal first step to make the agent functional, not an additional security opt-in. F-A4 and F-A5 do *not* require an LLM key (see per-finding notes); F1 and F3 do not require an LLM key for the unauth surface itself, only for the chained RCE demonstration in F1. ### Reproducer environment (common) ```sh git clone https://github.com/HKUDS/Vibe-Trading.git cd Vibe-Trading git checkout 7452610113a75529b5d55fd2217bb17f7bec66f7 # v0.1.6 + 1 frontend fix; same vuln state as v0.1.6 cp agent/.env.example agent/.env # (For F1 chained demo only:) edit agent/.env to set OPENROUTER_API_KEY=<real key> docker compose up -d # port 8899 is now reachable; HOST below is the docker host's IP from the attacker's perspective `

Properties

severity
critical
summary
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
cvss_score
10
retrieved_at
2026-10-03T18:15:00+00:00
ghsa_published
2026-10-02T22:44:26Z
source_url
https://github.com/advisories/GHSA-v2f8-6655-7grj
ghsa_updated
2026-10-02T22:44:28Z
ghsa_id
GHSA-v2f8-6655-7grj
last_source
GitHub Advisory Database
cve_id
GHSA-v2f8-6655-7grj
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
signal_observed_at
2026-10-03T01:59:23+00:00
is_ghsa_only
true

Related Entities (8)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]pip/vibe-trading-ai

AFFECTS (1)

→[Software]pip/vibe-trading-ai

HAS_WEAKNESS (5)

→[Weakness]Missing Authorization
→[Weakness]Exposure of Sensitive Information to an Unauthorized Actor
→[Weakness]Missing Authentication for Critical Function
→[Weakness]Permissive Cross-domain Security Policy with Untrusted Domains
→[Weakness]Unrestricted Upload of File with Dangerous Type

Explore deeper with Ninja Signal's threat intelligence graph