Aeon 库中的 方法存在代码注入漏洞,可导致远程代码执行。攻击者可通过此漏洞在受影响系统中执行任意代码。利用该漏洞需要用户交互,即目标必须访问恶意页面或打开恶意文件。 该漏洞的具体根源在于 方法中缺乏对用户提供的字符串进行适当的验证,便直接将其用于执行 Python 代码。攻击者可利用此漏洞,在当前进程上下文中执行恶意代码。此漏洞编号为 ZDI-CAN-29160。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18287 | Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerab | |
| CVE-2026-18285 | Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulne |
No comments yet