Product
Vibe-Trading v0.1.6 contains multiple critical vulnerabilities, including unauthenticated API access, unrestricted file uploads, and a command injection chain leading to container-level RCE when the API_AUTH_KEY is unset.