Rsbuild 2.0.9 之前的版本存在命令注入漏洞,允许攻击者通过向服务器提供包含 shell 元字符的精心构造的 URL,在 macOS 上执行任意操作系统命令。 具体而言,位于 中的 函数在将 URL 插入到通过 执行的 shell 命令之前,会先通过 对其进行编码。然而, 不会对美元符号($)、括号和分号进行编码,因此嵌入的 shell 元字符会被 解析并执行,从而实现任意命令执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| web-infra-dev | rsbuild | 0 ~ 2.0.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet