Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
GitButler: Link injection via forge integration enables arbitrary script execution
Vulnerability Description
GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execution vulnerability exists in the Tauri-based GitButler desktop application. An attacker can inject a malicious link in a pull request body, which if clicked by the user allows for arbitrary script execution in the Tauri webview. Users that have not enabled forge integration are not at risk. This vulnerability is fixed in 0.19.7.
CVSS Information
N/A
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
GitButler 代码注入漏洞
Vulnerability Description
GitButler是GitButler开源的一款支持AI工作流的现代Git版本控制界面。 GitButler 0.19.7之前版本存在代码注入漏洞,该漏洞源于拉取请求正文中的恶意链接可能导致Tauri webview中任意脚本执行。
CVSS Information
N/A
Vulnerability Type
N/A