GeekAI是GeekMaser个人开发者的一个大语言模型助手。 GeekAI 4.2.4及之前版本存在代码问题漏洞,该漏洞源于文件api/handler/net_handler.go中函数Download对参数url的操作不当,可能导致服务端请求伪造攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | GeekAI | 4.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-2542 | 7.0 HIGH | Total VPN win-service.exe unquoted search path |
| CVE-2026-2556 | 6.3 MEDIUM | cskefu Endpoint MediaController.java server-side request forgery |
| CVE-2026-2531 | 6.3 MEDIUM | MindsDB File Upload security.py clear_filename server-side request forgery |
| CVE-2026-2552 | 5.5 MEDIUM | ZenTao Editor control.php delete path traversal |
| CVE-2026-2551 | 5.4 MEDIUM | ZenTao Backup control.php delete path traversal |
| CVE-2026-2525 | 5.3 MEDIUM | Free5GC PFCP UDP Endpoint denial of service |
| CVE-2026-2524 | 5.3 MEDIUM | Open5GS MME mme_s11_handle_create_session_response denial of service |
| CVE-2026-2523 | 5.3 MEDIUM | Open5GS SMF gn-handler.c smf_gn_handle_create_pdp_context_request assertion |
| CVE-2026-2555 | 5.0 MEDIUM | JeecgBoot Retrieval-Augmented Generation AiragKnowledgeController.java importDocumentFromZ |
| CVE-2026-2557 | 3.5 LOW | cskefu File Upload MediaController.java upload cross site scripting |
| CVE-2026-2547 | 3.5 LOW | LigeroSmart index.pl AgentDashboard cross site scripting |
| CVE-2026-2546 | 3.5 LOW | LigeroSmart index.pl cross site scripting |
| CVE-2026-2545 | 3.5 LOW | LigeroSmart index.pl cross site scripting |
| CVE-2025-65716 | Markdown Preview Enhanced 安全漏洞 | |
| CVE-2025-65715 | Code Runner 安全漏洞 | |
| CVE-2025-65717 | Live Server 安全漏洞 |
No comments yet