CVE-2026-58169: Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that allows remote attackers to bypass bearer-token authentication by exploiting the server's trust of TCP pe...

Added to the CISA Known Exploited Vulnerabilities catalog on 30 Jun 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.5.

Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that allows remote attackers to bypass bearer-token authentication by exploiting the server's trust of TCP peer addresses for loopback clients combined with missing Host header validation while binding to 0.0....

Required action: Review and patch if applicable to your AI infrastructure.