SpeechBrain 在 1.1.1 之前存在一个任意代码执行漏洞。攻击者可以通过提供精心构造的 CKPT.yaml 检查点元数据文件,在 Checkpointer.recover_if_possible() 函数的候选枚举过程中,利用 PyYAML 的不安全加载器解析该文件,从而执行任意代码。攻击者可以在配置的检查点路径内的任意 CKPT.yaml 文件中嵌入恶意的 Python 对象构造标签(如 ),在候选发现阶段触发代码执行,即使该恶意检查点最终未被选中用于恢复操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| speechbrain | speechbrain | 0 ~ 1.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet