漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Repomix: attach_packed_output can bypass file-read secret scanning for supported local files
Vulnerability Description
Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_output and read_repomix_output flow can register and read arbitrary local .json, .txt, .md, or .xml files without the file_system_read_file runSecretLint() safety check or Repomix packed-output validation, allowing MCP callers to bypass the local file-read secret-scanning boundary. This issue is fixed in version 1.14.1.
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
信息暴露
Vulnerability Title
Kazuki Yamada Repomix 信息泄露漏洞
Vulnerability Description
Kazuki Yamada Repomix是Kazuki Yamada个人开发者开源的一款代码仓库打包与整合工具。 Kazuki Yamada Repomix 1.14.1之前版本存在信息泄露漏洞,该漏洞源于MCP server的attach_packed_output和read_repomix_output流程未经过安全检查和打包输出验证,允许MCP调用者绕过本地文件读取的机密扫描边界,导致注册和读取任意本地.json、.txt、.md或.xml文件。
CVSS Information
N/A
Vulnerability Type
N/A