有报告称,天禧 AI Agent PC 应用程序(仅在中国市场分发)中可能存在一个命令注入漏洞。如果本地用户打开一个由该应用程序处理的、经过特殊构造的链接,就可能触发操作系统的命令执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Lenovo | Tianxi AI Agent PC Application | < 4.2.1.8111 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Lenovo | Tianxi AI Agent PC Application | 0 ~ 4.2.1.8111 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75940 | 9.1 CRITICAL | 联想健康App敏感健康信息泄露漏洞 |
| CVE-2026-11813 | 7.8 HIGH | Lenovo Filez Client权限不当致本地权限提升 |
| CVE-2026-63427 | 7.8 HIGH | Lenovo Software Fix 认证绕过致特权执行漏洞 |
| CVE-2026-18994 | 7.1 HIGH | 联想文件管理器授权不当致本地文件读写 |
No comments yet