GHSA-JQMF-MX4F-HFR6: GHSA-JQMF-MX4F-HFR6: Multiple Remote Code Execution and Security Flaws in Vibe-Trading AI-Agent Pipeline A security analysis of the Vibe-Trading AI-agent pipeline (vibe-trading-ai) disclosed multiple critical vulnerabilities, tracked as GHSA-JQMF-MX4F-HFR6 with a CVSS score of 10.0, allowing unauthenticated remote attackers to execute arbitrary OS commands and Python code as root. The flaws stem from direct shell execution in agent tool workflows, unsafe dynamic module loading, and SSRF points in versions before 0.1.7. A public proof-of-concept exploit exists, and the report recommends upgrading to 0.1.7, running the service as a non-privileged user, and restricting API ports to localhost. GHSA-JQMF-MX4F-HFR6: Multiple Remote Code Execution and Security Flaws in Vibe-Trading AI-Agent Pipeline Vulnerability ID: GHSA-JQMF-MX4F-HFR6 CVSS Score: 10.0 Published: 2026-10-02 An in-depth technical analysis of multiple critical security flaws identified in the Vibe-Trading ecosystem vibe-trading-ai . These issues range from unauthenticated remote command injection via agent tool executions to arbitrary Python execution through dynamic module loading and unsafe Jinja2 template autoescaping, allowing full system compromise. TL;DR Unauthenticated remote attackers can execute arbitrary OS commands and Python scripts as root via vulnerable AI-agent tool workflows, backtest runner dynamics, and SSRF points in Vibe-Trading < 0.1.7. ⚠️ Exploit Status: POC Technical Details - CWE ID : CWE-78, CWE-94, CWE-918 - Attack Vector : Network / Unauthenticated API Request - CVSS v3.1 : 10.0 Critical - CVSS v4.0 : 9.3 Critical - Exploit Status : Proof-of-Concept PoC Publicly Available - Impact : Remote Code Execution RCE / Full System Compromise - Root Cause : Direct shell execution, unsafe dynamic imports, and lack of authentication defaults Affected Systems - Vibe-Trading API service - vibe-trading-ai python package - Vibe-Trading backtest execution environment - vibe-trading-ai : = 0.1.0, < 0.1.7 Fixed in: 0.1.7 Code Analysis Implement core API authentication, opt-in policies for shell tools, path traversal checks, and AST structural verification of dynamic python script modules. Exploit Details Mitigation Strategies - Disable powerful shell utilities by ensuring VIBE TRADING ENABLE SHELL TOOLS is not set to 1. - Enforce API token authentication policies using unique API keys verified via hmac.compare digest. - Perform static analysis of all LLM-generated modules with Python's ast framework before dynamic loading. Remediation Steps: 1. Upgrade the python package vibe-trading-ai to version 0.1.7 or higher. 2. Implement the non-privileged service user 'vibe' in Dockerfile configurations. 3. Map API ports only to 127.0.0.1 within docker-compose.yml files. References Read the full report for GHSA-JQMF-MX4F-HFR6 on our website https://cvereports.com/reports/GHSA-JQMF-MX4F-HFR6 for more details including interactive diagrams and full exploit analysis.