Upsonic是Upsonic开源的一个AI代理框架。 Upsonic 0.55.6及之前版本存在代码问题漏洞,该漏洞源于组件Pickle Handler中文件/tools/add_tool函数cloudpickle.loads存在反序列化。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Upsonic | 0.55.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-6278 | 5.5 MEDIUM | Upsonic server.py os.path.join path traversal |
| CVE-2025-6270 | 5.3 MEDIUM | HDF5 H5FSsection.c H5FS__sect_find_node heap-based overflow |
| CVE-2025-6269 | 5.3 MEDIUM | HDF5 H5Cimage.c H5C__reconstruct_cache_entry heap-based overflow |
| CVE-2025-6272 | 3.3 LOW | wasm3 m3_compile.c MarkSlotAllocated out-of-bounds write |
| CVE-2025-6271 | 3.3 LOW | swftools wav2swf wav.c wav_convert2mono out-of-bounds |
No comments yet