vibe-trading-ai has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was October 2026 with 3. The median CVSS is 10.0 (critical), with 2 rated critical.
CVEs per month
Last 12 months, by publish date
1125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/091026/10
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 10.0
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
3
Total CVEs
2
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
GHSA-v2f8-6655-7grjCritical· 10.0Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain55GHSA-jqmf-mx4f-hfr6Critical· 10.0Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF55GHSA-5rmq-chc7-m22fHigh· 7.5Vibe-Trading file-read tools expose arbitrary server-readable files41
vibe-trading-ai vulnerabilities
CVEs affecting vibe-trading-ai, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
GHSA-jqmf-mx4f-hfr6Critical· 10.0Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF
▾ Midnightvibe-trading-ai · vibe-trading-aivia GHSA
GHSA-5rmq-chc7-m22fHigh· 7.5Vibe-Trading file-read tools expose arbitrary server-readable files
Vibe-Trading file-read tools expose arbitrary server-readable files
▾ Twilightvibe-trading-ai · vibe-trading-aivia GHSA
GHSA-v2f8-6655-7grjCritical· 10.0Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
▾ Midnightvibe-trading-ai · vibe-trading-aivia GHSA