mosaxiv clawlet是mosaxiv个人开发者的一款服务器管理软件。 mosaxiv clawlet 0.2.0版本、0.2.1版本、0.2.2版本、0.2.3版本、0.2.4版本、0.2.5版本、0.2.6版本、0.2.7版本、0.2.8版本、0.2.9版本和0.2.10版本存在后置链接漏洞,该漏洞源于File Tools组件tools/fs_ops.go文件中的read_file/write_file/edit_file函数存在问题,导致链接跟随,攻击者需本地发起攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15619 | 6.3 MEDIUM | mosaxiv clawlet IPv4 tool_web_fetch.go web_fetch server-side request forgery |
| CVE-2026-15620 | 6.3 MEDIUM | mosaxiv clawlet tool_web_fetch.go tools.webFetch server-side request forgery |
No comments yet