在腾讯 AI-Infra-Guard 4.5.2 及 4.6.2 之前版本中发现了一个漏洞。该漏洞影响 File Access 组件中 skill_scan/tools/dir/dir_actions.py 文件的 startsWith 函数。此漏洞可导致路径遍历。攻击必须在本机执行。利用代码已公开,可能被攻击者使用。升级至 4.6.0 版本可缓解此问题。补丁标识为 ac0384edc9dbea3b226edefcf50613bd8509134f。建议尽快升级受影响的组件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Tencent | AI-Infra-Guard | 4.5.0 |
cpe:2.3:a:tencent:ai-infra-guard:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet