WSO2 Integrator MI 的 VS Code 扩展在处理来自不可信源打开的 Micro Integrator 项目时,未能对用户输入进行适当的净化或验证。这使得精心构造的项目能够通过单元测试执行流程注入并执行任意操作系统命令。 成功利用此漏洞可在 VS Code 扩展运行的系统上执行任意操作系统命令。影响范围取决于 VS Code 运行所使用的用户账户权限。利用该漏洞需要用户先为恶意项目授予工作区信任(workspace trust),随后触发单元测试执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WSO2 | WSO2 Integrator: MI for Visual Studio Code | 0 ~ 4.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-5802 | 5.3 MEDIUM | Username Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Acco |
| CVE-2025-13166 | 3.7 LOW | Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account Discover |
No comments yet