GenOffice 最高至版本 0.11.505 中存在一个不正确的权限漏洞,位于其 HTTP MCP 服务器的文件存储模块。该漏洞允许本地未授权用户读取已上传和生成的文档。攻击者可以通过列出系统临时目录下的全局可读目录 ,来读取客户端上传的文件以及转换后的输出内容,从而绕过 HTTP Bearer Token 的身份验证机制。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| genspark-ai | GenOffice | ≤ 0.11.505 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| genspark-ai | GenOffice | 0 ~ 0.11.505 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet