漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
GitButler: Link injection via forge integration enables arbitrary script execution
Vulnerability Description
GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execution vulnerability exists in the Tauri-based GitButler desktop application. An attacker can inject a malicious link in a pull request body, which if clicked by the user allows for arbitrary script execution in the Tauri webview. Users that have not enabled forge integration are not at risk. This vulnerability is fixed in 0.19.7.
CVSS Information
N/A
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
GitButler 代码注入漏洞
Vulnerability Description
GitButler是GitButler开源的一款支持AI工作流的现代Git版本控制界面。 GitButler 0.19.7之前版本存在代码注入漏洞,该漏洞源于拉取请求正文中的恶意链接可能导致Tauri webview中任意脚本执行。
CVSS Information
N/A
Vulnerability Type
N/A