漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
[Kimi VS Code] Command Injection in publish scripts vsix-publish.js and ovsx-publish.js
Vulnerability Description
Kimi Agent SDK is a set of libraries that expose the Kimi Code (Kimi CLI) agent runtime in applications. The vsix-publish.js and ovsx-publish.js scripts pass filenames to execSync() as shell command strings. Prior to version 0.1.6, filenames containing shell metacharacters like $(cmd) could execute arbitrary commands. Note: This vulnerability exists only in the repository's development scripts. The published VSCode extension does not include these files and end users are not affected. This is fixed in version 0.1.6 by replacing execSync with execFileSync using array arguments. As a workaround, ensure .vsix files in the project directory have safe filenames before running publish scripts.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
Kimi Agent SDK 命令注入漏洞
Vulnerability Description
Kimi Agent SDK是Moonshot AI开源的一套可将Kimi Code代理运行时集成到应用程序中的多语言库。 Kimi Agent SDK 0.1.6之前版本存在命令注入漏洞,该漏洞源于开发脚本将文件名作为shell命令字符串传递,可能导致命令注入。
CVSS Information
N/A
Vulnerability Type
N/A