在 SciPhi-AI R2R(最高至 3.6.6 版本)中识别出一项漏洞。该漏洞影响组件“检索补全 API 端点”(Retrieval Completion API Endpoint)中文件 的未知代码。对参数 的操纵可导致服务器端请求伪造(SSRF)。该攻击可由远程发起,相关漏洞利用代码已公开,存在被实际利用的风险。厂商虽在披露早期即被联系,但始终未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet