Michael White Frogman是Michael White个人开发者的一款通过 MCP 和 HTTP API 实现无头 PBX 控制的软件。 Michael White Frogman 1.6.2之前版本存在代码注入漏洞,该漏洞源于fm_dialplan_apply接受包括greeting、dest、url、extension、code和file的模板参数,且仅对contextName()进行了清理,允许具有PERM_WRITE权限并使用confirm:true的调用者注入任意Asterisk
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-46513 | 7.4 HIGH | Frogman: API tokens stored in plaintext |
| CVE-2026-46514 | 6.5 MEDIUM | Frogman: Plaintext passwords and secrets persisted to audit log |
| CVE-2026-46515 | Frogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution |
No comments yet