phi 0.1.1 至 0.28.4 版本存在一个不正确的链接解析漏洞,攻击者可以利用权限检查中仅基于词法的路径检查机制,绕过 workspace_only_writes 限制。具体而言,攻击者可以在仓库中提交指向工作区外部的符号链接(symlink),并结合提示注入(prompt injection)技术,诱导写入工具在未经批准的情况下将受攻击者控制的恶意内容写入外部文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pulseaiclub | phi | 0.1.1≤ 0.28.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pulseaiclub | phi | 0.1.1 ~ 0.28.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet