{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vibe-trading-ai--0.1.0--0.1.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["vibe-trading-ai (\u003e= 0.1.0, \u003c 0.1.7)"],"_cs_severities":["high"],"_cs_tags":["path-traversal","llm-security","cloud-security","information-disclosure"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eVibe-Trading-AI versions 0.1.0 through 0.1.6 contain two critical file-read vulnerabilities arising from insufficient input validation within its LLM tool registry. The utility \u003ccode\u003esafe_user_path()\u003c/code\u003e in \u003ccode\u003epath_utils.py\u003c/code\u003e incorrectly allows access to any path within the user home directory and current working directory. In the default Docker container deployment, this grants access to sensitive files under \u003ccode\u003e/root\u003c/code\u003e and \u003ccode\u003e/app\u003c/code\u003e, such as \u003ccode\u003e/root/.ssh/id_rsa\u003c/code\u003e, \u003ccode\u003e/root/.aws/credentials\u003c/code\u003e, and \u003ccode\u003e/app/agent/.env\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eFurthermore, the \u003ccode\u003eread_document()\u003c/code\u003e function in \u003ccode\u003edoc_reader_tool.py\u003c/code\u003e lacks any sandbox enforcement, allowing the application to open and return the contents of any file the process can read, including \u003ccode\u003e/etc/shadow\u003c/code\u003e, \u003ccode\u003e/etc/passwd\u003c/code\u003e, and \u003ccode\u003e/proc/self/environ\u003c/code\u003e. As the application runs as root within the container, these flaws allow unauthenticated attackers to exfiltrate secrets and system configuration files. These vulnerabilities are accessible via TCP port 8899 without authentication, facilitating unauthorized data access and potential full environment compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes an unauthenticated session with the target Vibe-Trading-AI service on port 8899 via a crafted HTTP POST request.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the LLM-driven agent by submitting a message containing a request to read or analyze a specific sensitive file path (e.g., \u003ccode\u003e/proc/self/environ\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe agent maps the request to the \u003ccode\u003eread_document()\u003c/code\u003e tool or a tool gated by \u003ccode\u003esafe_user_path()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe tool fails to perform adequate path validation, bypassing the intended security sandbox due to the lack of restrictive checks in \u003ccode\u003eread_document()\u003c/code\u003e or the overly broad envelope in \u003ccode\u003esafe_user_path()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe application opens the target file on the host container filesystem with root privileges.\u003c/li\u003e\n\u003cli\u003eThe content of the file (e.g., plaintext API keys or shadow passwords) is returned to the agent's message buffer.\u003c/li\u003e\n\u003cli\u003eAttacker polls the session messages to retrieve the full content or the first line of the targeted file, successfully exfiltrating credentials.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to read any file on the container filesystem. Observed impacts include the exfiltration of sensitive environment variables (API keys), SSH keys, cloud credentials, and system authentication files like \u003ccode\u003e/etc/shadow\u003c/code\u003e. This leads to the total compromise of the application's security posture and potentially facilitates further lateral movement or unauthorized access to integrated cloud resources.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching and architectural hardening to mitigate these path traversal risks.\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade to Vibe-Trading-AI version 0.1.7 or later to implement the restricted file-read envelopes and input sanitization.\u003c/li\u003e\n\u003cli\u003eApply the specific code-level remediation: Replace the \u003ccode\u003ePath.home() ∪ Path.cwd()\u003c/code\u003e envelope in \u003ccode\u003esafe_user_path()\u003c/code\u003e with an explicit, restrictive allowlist of directories, and ensure \u003ccode\u003eread_document()\u003c/code\u003e invokes a validated sandbox function prior to file operations.\u003c/li\u003e\n\u003cli\u003eEnforce the Principle of Least Privilege by modifying the Dockerfile to run the FastAPI process as a non-root user (e.g., \u003ccode\u003eUSER vibe\u003c/code\u003e) rather than the default root user.\u003c/li\u003e\n\u003cli\u003eImplement network-level access controls to restrict exposure of the agent API port (8899) to trusted IP addresses only.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-02T22:49:56Z","date_published":"2026-10-02T22:49:56Z","id":"https://feed.craftedsignal.io/briefs/2026-10-vibe-trading-path-traversal/","summary":"Vibe-Trading-AI versions 0.1.0 through 0.1.6 contain path traversal vulnerabilities allowing unauthenticated attackers to read arbitrary files from the container filesystem due to overly permissive sandbox checks and a missing security envelope.","title":"Arbitrary File Read Vulnerabilities in Vibe-Trading-AI","url":"https://feed.craftedsignal.io/briefs/2026-10-vibe-trading-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Vibe-Trading-Ai (\u003e= 0.1.0, \u003c 0.1.7)","version":"https://jsonfeed.org/version/1.1"}