Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
nearai ironclaw shell.rs classify_command_risk command injection
Vulnerability Description
A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is a1d7c3ba428ed575900469b207fb5668725f9a71. Applying a patch is advised to resolve this issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
NEAR AI IronClaw 输入验证错误漏洞
Vulnerability Description
NEAR AI IronClaw是美国NEAR AI组织的一款服务器系统软件。 NEAR AI IronClaw 0.29.1及之前版本存在安全漏洞,该漏洞源于src/tools/builtin/shell.rs文件中的classify_command_risk函数处理不当,可能导致命令注入。
CVSS Information
N/A
Vulnerability Type
N/A