Arbitrary File Read Vulnerabilities in Vibe-Trading-AI
Vibe-Trading-AI versions 0.1.0 through 0.1.6 contain path traversal vulnerabilities allowing unauthenticated attackers to read arbitrary files from the container filesystem due to overly permissive sandbox checks and a missing security envelope.
Vibe-Trading-AI versions 0.1.0 through 0.1.6 contain two critical file-read vulnerabilities arising from insufficient input validation within its LLM tool registry. The utility safe_user_path() in path_utils.py incorrectly allows access to any path within the user home directory and current working directory. In the default Docker container deployment, this grants access to sensitive files under /root and /app, such as /root/.ssh/id_rsa, /root/.aws/credentials, and /app/agent/.env.
Furthermore, the read_document() function in doc_reader_tool.py lacks any sandbox enforcement, allowing the application to open and return the contents of any file the process can read, including /etc/shadow, /etc/passwd, and /proc/self/environ. As the application runs as root within the container, these flaws allow unauthenticated attackers to exfiltrate secrets and system configuration files. These vulnerabilities are accessible via TCP port 8899 without authentication, facilitating unauthorized data access and potential full environment compromise.
Attack Chain
- Attacker establishes an unauthenticated session with the target Vibe-Trading-AI service on port 8899 via a crafted HTTP POST request.
- Attacker interacts with the LLM-driven agent by submitting a message containing a request to read or analyze a specific sensitive file path (e.g.,
/proc/self/environ). - The agent maps the request to the
read_document()tool or a tool gated bysafe_user_path(). - The tool fails to perform adequate path validation, bypassing the intended security sandbox due to the lack of restrictive checks in
read_document()or the overly broad envelope insafe_user_path(). - The application opens the target file on the host container filesystem with root privileges.
- The content of the file (e.g., plaintext API keys or shadow passwords) is returned to the agent's message buffer.
- Attacker polls the session messages to retrieve the full content or the first line of the targeted file, successfully exfiltrating credentials.
Impact
Successful exploitation allows unauthenticated attackers to read any file on the container filesystem. Observed impacts include the exfiltration of sensitive environment variables (API keys), SSH keys, cloud credentials, and system authentication files like /etc/shadow. This leads to the total compromise of the application's security posture and potentially facilitates further lateral movement or unauthorized access to integrated cloud resources.
Recommendation
Prioritize patching and architectural hardening to mitigate these path traversal risks.
- Upgrade to Vibe-Trading-AI version 0.1.7 or later to implement the restricted file-read envelopes and input sanitization.
- Apply the specific code-level remediation: Replace the
Path.home() ∪ Path.cwd()envelope insafe_user_path()with an explicit, restrictive allowlist of directories, and ensureread_document()invokes a validated sandbox function prior to file operations. - Enforce the Principle of Least Privilege by modifying the Dockerfile to run the FastAPI process as a non-root user (e.g.,
USER vibe) rather than the default root user. - Implement network-level access controls to restrict exposure of the agent API port (8899) to trusted IP addresses only.
Immediate actions
Upgrade Vibe-Trading-AI to version 0.1.7 or later
Mitigations
Modify Dockerfile to run application as a non-root user
Blast radius of path traversal findings