VYPR

Vibe-Trading

by Hkuds

CVEs (4)

  • CVE-2026-58173Jun 30, 2026
    risk 0.00cvss epss 0.00

    Vibe-Trading before 0.1.10 contains a path traversal vulnerability that allows attackers to write files outside the intended memory root directory by supplying a malicious memory_type value containing path traversal sequences through the remember tool. Attackers can manipulate…

  • CVE-2026-58171Jun 30, 2026
    risk 0.00cvss epss 0.00

    Vibe-Trading before 0.1.10 constructs the swarm run directory by joining a caller-supplied run identifier onto the runs base directory without validation in run_dir (agent/src/swarm/store.py). A crafted run identifier supplied through the MCP swarm tools causes the application…

  • CVE-2026-58170Jun 30, 2026
    risk 0.00cvss epss 0.00

    Vibe-Trading before 0.1.10 builds the proposal file path by joining a caller-supplied proposal identifier onto the broker proposals directory without sanitization (agent/src/live/mandate/commit.py). A proposal identifier containing path traversal sequences causes the application…

  • CVE-2026-58169Jun 30, 2026
    risk 0.00cvss epss 0.00

    Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that allows remote attackers to bypass bearer-token authentication by exploiting the server's trust of TCP peer addresses for loopback clients combined with missing Host header validation…