Vulnerability  ·  2026-10-06

HKUDS Vibe-Trading LLM trading agent: unauthenticated MCP/API exposes shell RCE, file read and credential theft (GHSA-v2f8-6655-7grj / GHSA-jqmf-mx4f-hfr6 / GHSA-5rmq-chc7-m22f)

VulnerabilityHigh impactGlobalnull
Three GitHub-reviewed advisories for the HKUDS Vibe-Trading open-source LLM trading agent entered the GitHub Advisory Database on 2026-10-02 (research credited to lemi9090), covering an unauthenticated FastAPI surface leading to root shell (CVSS 10.0), LLM-callable shell/code tools plus SSRF (CVSS 10.0), and unrestricted file-read tools (CVSS 7.5) in versions 0.1.0-0.1.6. The advisories demonstrate plaintext theft of broker, LLM-provider (e.g. OPENROUTER_API_KEY) and cloud keys, plus prompt-injection steering of the agent into the same tools; the underlying flaw was fixed in v0.1.7 (May 2026) with additional later CVEs patched only by 0.1.10, and 0.1.16 is the current supported release.
This is a full chain on an actual agentic AI system that holds high-value financial and LLM credentials: an internet-reachable, unauthenticated control surface over an autonomous trading agent yields arbitrary command execution as root, credential theft, and memory/data exposure — plus a prompt-injection path that abuses the agent itself even when the API is locked down. Defenders running or exposing such frameworks should treat default-auth-off as an immediate incident trigger.
With API_AUTH_KEY unset by default, every guarded endpoint is anonymous; an unauthenticated network client can POST to /sessions/{id}/messages and drive the LLM agent's BashTool to run arbitrary shell commands as root in the container (and separately trigger code execution through the backtest exec_module path). Unauthenticated file upload of Python/shell/config files, plus file-read tools able to read ~/.ssh, /root/.aws/credentials, .env (containing broker/LLM/market-data API keys) and /proc/self/environ. Read endpoints return full session history even when API_AUTH_KEY is set. A second, harder-to-detect path: prompt injection through documents/web pages steers a legitimate agent session into the same tools.
HKUDS vibe-trading-ai versions 0.1.0 through 0.1.6 (GHSA-advisory fixed in 0.1.7); note later CVEs (CVE-2026-58169/-58170/-58171/-58173) extend exposure to before 0.1.10; current release 0.1.16
Upgrade to vibe-trading-ai 0.1.16; for any deployment, set API_AUTH_KEY, bind the API to localhost, and rotate any API keys that were present in .env or environment of exposed instances. Advisories: https://github.com/advisories/GHSA-v2f8-6655-7grj, https://github.com/advisories/GHSA-jqmf-mx4f-hfr6, https://github.com/advisories/GHSA-5rmq-chc7-m22f
GitHub Advisory GHSA-v2f8-6655-7grjGitHub Advisory GHSA-jqmf-mx4f-hfr6GitHub Advisory GHSA-5rmq-chc7-m22f
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →