Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
PinchTab: SSRF with Full Response Exfiltration via Download Handler
Vulnerability Description
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Prior to version 0.7.7, a Server-Side Request Forgery (SSRF) vulnerability in the /download endpoint allows any user with API access to induce the PinchTab server to make requests to arbitrary URLs, including internal network services and local system files, and exfiltrate the full response content. This issue has been patched in version 0.7.7.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
pinchtab 代码问题漏洞
Vulnerability Description
pinchtab是Pinchtab开源的一个AI代理浏览器控制工具。 pinchtab 0.7.7之前版本存在代码问题漏洞,该漏洞源于/download端点存在服务端请求伪造,可能导致服务器向任意URL发起请求并泄露响应内容。
CVSS Information
N/A
Vulnerability Type
N/A