漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
zevorn rt-claw Telegram-to-AI Tool Execution Flow script.c tool_run_script_execute code injection
Vulnerability Description
A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This affects the function tool_run_script_execute of the file claw/services/tools/script.c of the component Telegram-to-AI Tool Execution Flow. Performing a manipulation results in code injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
Zevorn RT-Claw 输入验证错误漏洞
Vulnerability Description
Zevorn RT-Claw是中国Zevorn个人开发者开源的一款面向嵌入式设备的智能助手。 Zevorn RT-Claw 0.2.0及之前版本存在安全漏洞,该漏洞源于Telegram-to-AI Tool Execution Flow组件的文件claw/services/tools/script.c中函数tool_run_script_execute存在操作问题,导致代码注入。
CVSS Information
N/A
Vulnerability Type
N/A