在 unitedbyai droidclaw(最高版本至 0.5.3)中发现了一个安全弱点。该漏洞影响组件“Unsigned Scheduled Callback”中文件 的某些未知功能。此漏洞可导致授权绕过。攻击可被远程利用。该攻击被评估为具有较高复杂性,实际利用难度较大。目前该漏洞的利用代码已公开,可能被攻击者滥用。项目方已通过 issue 报告在早期获知此问题,但至今尚未作出回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| unitedbyai | droidclaw | 0.5.0 |
affected |
0.5.1 |
affected | ||
0.5.2 |
affected | ||
0.5.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| unitedbyai | droidclaw | 0.5.0 |
cpe:2.3:a:unitedbyai:droidclaw:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet