漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Heym < 0.0.21 Path Traversal File Upload via upload_file()
Vulnerability Description
Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write attacker-controlled files to arbitrary locations by supplying a crafted filename with traversal sequences. Attackers can exploit the unvalidated filename parameter in the upload_file() handler to bypass path restrictions and write, read, or delete files outside the intended storage directory.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Heym 路径遍历漏洞
Vulnerability Description
Heym是heymrun开源的一个AI原生工作流自动化平台。 Heym 0.0.21之前版本存在路径遍历漏洞,该漏洞源于文件上传端点存在路径遍历,可能导致经过身份验证的用户通过提供带有遍历序列的特制文件名,将攻击者控制的文件写入任意位置。
CVSS Information
N/A
Vulnerability Type
N/A