GitAhead 2.7.1 及更早版本在 macOS 上存在命令注入漏洞,攻击者可通过构造经过插值处理但未转义的文件名,从而在“在 Finder 中显示”(Show in Finder)AppleScript 中执行 Shell 命令。攻击者可以提交一个文件名包含双引号并紧随 Shell 命令载荷的文件,当受害者选择“在 Finder 中显示”时,该命令将以受害者用户的权限执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet