ai-goofish-monitor是Usagi-org开源的一个基于AI的多任务实时监控与Web管理工具。 ai-goofish-monitor存在安全漏洞,该漏洞源于Windows部署中GET /api/prompts/{filename}端点存在未经验证的任意文件读取漏洞,可能导致未经验证的远程攻击者通过提供绝对Windows路径或基于反斜杠的遍历序列读取任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Usagi-org | ai-goofish-monitor | < f85d140b6b45029d9a0925feb96dad733b41396d |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Usagi-org | ai-goofish-monitor | 0 ~ f85d140b6b45029d9a0925feb96dad733b41396d | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet