<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Vibe-Trading-Ai (&gt;= 0.1.0, &lt; 0.1.7) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/vibe-trading-ai--0.1.0--0.1.7/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 22:49:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/vibe-trading-ai--0.1.0--0.1.7/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary File Read Vulnerabilities in Vibe-Trading-AI</title><link>https://feed.craftedsignal.io/briefs/2026-10-vibe-trading-path-traversal/</link><pubDate>Fri, 02 Oct 2026 22:49:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-vibe-trading-path-traversal/</guid><description>Vibe-Trading-AI versions 0.1.0 through 0.1.6 contain path traversal vulnerabilities allowing unauthenticated attackers to read arbitrary files from the container filesystem due to overly permissive sandbox checks and a missing security envelope.</description><content:encoded><![CDATA[<p>Vibe-Trading-AI versions 0.1.0 through 0.1.6 contain two critical file-read vulnerabilities arising from insufficient input validation within its LLM tool registry. The utility <code>safe_user_path()</code> in <code>path_utils.py</code> incorrectly allows access to any path within the user home directory and current working directory. In the default Docker container deployment, this grants access to sensitive files under <code>/root</code> and <code>/app</code>, such as <code>/root/.ssh/id_rsa</code>, <code>/root/.aws/credentials</code>, and <code>/app/agent/.env</code>.</p>
<p>Furthermore, the <code>read_document()</code> function in <code>doc_reader_tool.py</code> lacks any sandbox enforcement, allowing the application to open and return the contents of any file the process can read, including <code>/etc/shadow</code>, <code>/etc/passwd</code>, and <code>/proc/self/environ</code>. As the application runs as root within the container, these flaws allow unauthenticated attackers to exfiltrate secrets and system configuration files. These vulnerabilities are accessible via TCP port 8899 without authentication, facilitating unauthorized data access and potential full environment compromise.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker establishes an unauthenticated session with the target Vibe-Trading-AI service on port 8899 via a crafted HTTP POST request.</li>
<li>Attacker interacts with the LLM-driven agent by submitting a message containing a request to read or analyze a specific sensitive file path (e.g., <code>/proc/self/environ</code>).</li>
<li>The agent maps the request to the <code>read_document()</code> tool or a tool gated by <code>safe_user_path()</code>.</li>
<li>The tool fails to perform adequate path validation, bypassing the intended security sandbox due to the lack of restrictive checks in <code>read_document()</code> or the overly broad envelope in <code>safe_user_path()</code>.</li>
<li>The application opens the target file on the host container filesystem with root privileges.</li>
<li>The content of the file (e.g., plaintext API keys or shadow passwords) is returned to the agent's message buffer.</li>
<li>Attacker polls the session messages to retrieve the full content or the first line of the targeted file, successfully exfiltrating credentials.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to read any file on the container filesystem. Observed impacts include the exfiltration of sensitive environment variables (API keys), SSH keys, cloud credentials, and system authentication files like <code>/etc/shadow</code>. This leads to the total compromise of the application's security posture and potentially facilitates further lateral movement or unauthorized access to integrated cloud resources.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching and architectural hardening to mitigate these path traversal risks.</p>
<ol>
<li>Upgrade to Vibe-Trading-AI version 0.1.7 or later to implement the restricted file-read envelopes and input sanitization.</li>
<li>Apply the specific code-level remediation: Replace the <code>Path.home() ∪ Path.cwd()</code> envelope in <code>safe_user_path()</code> with an explicit, restrictive allowlist of directories, and ensure <code>read_document()</code> invokes a validated sandbox function prior to file operations.</li>
<li>Enforce the Principle of Least Privilege by modifying the Dockerfile to run the FastAPI process as a non-root user (e.g., <code>USER vibe</code>) rather than the default root user.</li>
<li>Implement network-level access controls to restrict exposure of the agent API port (8899) to trusted IP addresses only.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>path-traversal</category><category>llm-security</category><category>cloud-security</category><category>information-disclosure</category></item></channel></rss>