cd /news/ai-agents/ghsa-jqmf-mx4f-hfr6-ghsa-jqmf-mx4f-h… · home › topics › ai-agents › article
[ARTICLE · art-144502] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

GHSA-JQMF-MX4F-HFR6: GHSA-JQMF-MX4F-HFR6: Multiple Remote Code Execution and Security Flaws in Vibe-Trading AI-Agent Pipeline

A security analysis of the Vibe-Trading AI-agent pipeline (vibe-trading-ai) disclosed multiple critical vulnerabilities, tracked as GHSA-JQMF-MX4F-HFR6 with a CVSS score of 10.0, allowing unauthenticated remote attackers to execute arbitrary OS commands and Python code as root. The flaws stem from direct shell execution in agent tool workflows, unsafe dynamic module loading, and SSRF points in versions before 0.1.7. A public proof-of-concept exploit exists, and the report recommends upgrading to 0.1.7, running the service as a non-privileged user, and restricting API ports to localhost.

read2 min views1 publishedOct 3, 2026

#

  GHSA-JQMF-MX4F-HFR6: Multiple Remote Code Execution and Security Flaws in Vibe-Trading AI-Agent Pipeline

**Vulnerability ID:** GHSA-JQMF-MX4F-HFR6

CVSS Score: 10.0

Published: 2026-10-02 An in-depth technical analysis of multiple critical security flaws identified in the Vibe-Trading ecosystem (vibe-trading-ai). These issues range from unauthenticated remote command injection via agent tool executions to arbitrary Python execution through dynamic module and unsafe Jinja2 template autoescaping, allowing full system compromise.

#

TL;DR

Unauthenticated remote attackers can execute arbitrary OS commands and Python scripts as root via vulnerable AI-agent tool workflows, backtest runner dynamics, and SSRF points in Vibe-Trading < 0.1.7.

⚠️ Exploit Status: POC

#

Technical Details

CWE ID : CWE-78, CWE-94, CWE-918 #

Attack Vector : Network / Unauthenticated API Request #

CVSS v3.1 : 10.0 (Critical) #

CVSS v4.0 : 9.3 (Critical) #

Exploit Status : Proof-of-Concept (PoC) Publicly Available #

Impact : Remote Code Execution (RCE) / Full System Compromise #

Root Cause : Direct shell execution, unsafe dynamic imports, and lack of authentication defaults

#

Affected Systems

- Vibe-Trading API service
- vibe-trading-ai python package
  • Vibe-Trading backtest execution environment

vibe-trading-ai : >= 0.1.0, < 0.1.7 (Fixed in:0.1.7 )

#

Code Analysis

Implement core API authentication, opt-in policies for shell tools, path traversal checks, and AST structural verification of dynamic python script modules.

#

Exploit Details

#

Mitigation Strategies

  • Disable powerful shell utilities by ensuring VIBE_TRADING_ENABLE_SHELL_TOOLS is not set to 1.
  • Enforce API token authentication policies using unique API keys verified via hmac.compare_digest.
  • Perform static analysis of all LLM-generated modules with Python's ast framework before dynamic .

Remediation Steps:

  1. Upgrade the python package vibe-trading-ai to version 0.1.7 or higher.
  2. Implement the non-privileged service user 'vibe' in Dockerfile configurations.
  3. Map API ports only to 127.0.0.1 within docker-compose.yml files.

#

References

Read the full report for GHSA-JQMF-MX4F-HFR6 on our website for more details including interactive diagrams and full exploit analysis.

── more in #ai-agents 4 stories · sorted by recency
── more on @vibe-trading 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/ghsa-jqmf-mx4f-hfr6-…] indexed:0 read:2min 2026-10-03 · —