Vibe-Trading Unauthenticated RCE and API Exposure
Vibe-Trading v0.1.6 contains multiple critical vulnerabilities, including unauthenticated API access, unrestricted file uploads, and a command injection chain leading to container-level RCE when the API_AUTH_KEY is unset.
Vibe-Trading v0.1.6 and earlier versions are affected by several critical security flaws stemming from insecure default configurations. The application defaults to an unauthenticated state where the API_AUTH_KEY environment variable remains unset, causing the require_auth() dependency in FastAPI to return immediately without enforcing access controls. Because the application runs as root within a Docker container, this exposure provides an unauthenticated attacker with the ability to execute arbitrary shell commands via the BashTool functionality, resulting in full container takeover.
Beyond RCE, the application suffers from broken authorization on read-only endpoints, which remain accessible even when API_AUTH_KEY is configured. Additional vulnerabilities include an unrestricted file upload mechanism that allows attackers to write scripts (e.g., .py, .sh) to known paths, and a permissive CORS configuration that permits cross-origin requests from any local machine-served web application. These vulnerabilities, combined with the application's reliance on LLM tool-calling, present a high risk for data exfiltration and persistent malicious activity.
Attack Chain
- Attacker performs discovery against an exposed Vibe-Trading instance on TCP port 8899.
- Attacker confirms the lack of authentication by executing a POST request to
/sessionswithout anAuthorizationheader. - Attacker uses the
/sessionsendpoint to create a new session and obtain asession_id. - Attacker submits a crafted message to
/sessions/{session_id}/messagescontaining a natural language prompt designed to trigger the BashTool. - The ReAct agent selects
BashTool, which executessubprocess.run(command, shell=True)using the attacker-supplied input. - The command executes as root (UID 0) within the container environment, granting the attacker arbitrary code execution.
- Attacker uses the RCE primitive to exfiltrate sensitive environment variables, LLM API keys, or broker tokens stored in the container memory or file system.
Impact
Successful exploitation leads to full container takeover and potential compromise of the host environment if proper container isolation is missing. An attacker can exfiltrate sensitive data, including LLM API keys and broker credentials used for automated trading. Given the application's functionality, this can result in unauthorized financial transactions or persistent access to the victim's trading accounts. The vulnerabilities affect all instances deployed with default settings using the provided docker-compose.yml.
Recommendation
Prioritize the immediate securing of all Vibe-Trading instances by enforcing authentication.
- Set a strong
API_AUTH_KEYin the environment configuration and ensure the application is restarted with the new settings. - Implement a
USERdirective in theDockerfileto drop privileges from root to a non-privileged user. - Restrict network access to the API server to trusted source IP addresses using firewall rules or container network policies.
- Block or monitor all HTTP requests to the
/uploadand/sessionsendpoints that lack validAuthorizationheaders.
Immediate actions
Set API_AUTH_KEY in the agent environment to disable unauthenticated access to the FastAPI server
Mitigations
Configure container security to run the process as a non-root user and restrict access to port 8899
RCE vulnerability due to root execution and unauthenticated API