漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
louisho5 picobot Workspace filesystem.go GetSkill link following
Vulnerability Description
A weakness has been identified in louisho5 picobot up to 0.2.0. Impacted is the function CreateSkill/GetSkill of the file internal/agent/tools/filesystem.go of the component Workspace Handler. Executing a manipulation can lead to link following. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Vulnerability Title
Louis Picobot 后置链接漏洞
Vulnerability Description
Louis Picobot是中国Louis个人开发者的一款自动化流程调度软件。 Louis Picobot 0.2.0版本及之前版本存在后置链接漏洞,该漏洞源于Workspace Handler组件中文件internal/agent/tools/filesystem.go的函数CreateSkill/GetSkill存在后置链接问题,可能导致远程攻击。
CVSS Information
N/A
Vulnerability Type
N/A