Linqi是德国Linqi公司的一款结合真人语言交流与AI反馈的英语口语练习平台。 Linqi存在安全漏洞,该漏洞源于/api/Cdn/GetFile端点身份验证不当,导致未经身份验证的远程攻击者绕过文件访问控制,但实际安全影响可忽略。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| linqi GmbH | linqi | < 1.4.8.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| linqi GmbH | linqi | 0 ~ 1.4.8.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11369 | IDOR in Comment API Allows Cross-Process Comment Read and Write | |
| CVE-2026-11346 | Server-Side Request Forgery (SSRF) allowing Internal Network Probing in linqi | |
| CVE-2026-11347 | Hardcoded Cryptographic Keys and Weak IV Generation in linqi |
No comments yet