docling-project docling-core是docling-project组织的一款文档核心处理中间件。 docling-project docling-core 1.5.0版本至2.74.1之前版本存在安全漏洞,该漏洞源于未充分限制远程请求目的地,并以不安全的方式将服务器提供的Content-Disposition解析为本地路径,在接受不可信URL的应用中可能导致针对用户定义缓存目录外本地文件的服务端请求伪造攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| docling-project | docling-core | >= 1.5.0, < 2.74.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| docling-project | docling-core | >= 1.5.0, < 2.74.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: server-controlled Content-Disposition made docling-core write remote content to /flag.txt (secret exfiltrated: PROOF_f7d087fd0992b332)
No comments yet