Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-v2f8-6655-7grj
  • PyPI/vibe-trading-ai
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain yesterday
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-5rmq-chc7-m22f
  • PyPI/vibe-trading-ai
Vibe-Trading file-read tools expose arbitrary server-readable files yesterday
  • Fix available
  • Severity - 7.5 (High)
GHSA-jqmf-mx4f-hfr6
  • PyPI/vibe-trading-ai
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF yesterday
  • Fix available
  • Severity - 10.0 (Critical)