Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-51907

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 TaskingAI v0.3.0 的“二维码生成”(QR Code Generator)插件中, 函数存在路径遍历漏洞。攻击者通过操纵 参数,能够将图像文件写入服务器文件系统中的任意位置。

AI Predicted 7.5 Difficulty: Easy

Affected Version Matrix 1

VendorProduct Version RangeStatus
n/a n/a n/a affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-51907

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-51907

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-51907

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-51907 (1)

Proof of Concept for CVE-2026-51907 (1)

Same Patch Batch · n/a · 2026-10-02 · 14 CVEs total

CVE-2026-51906 TaskingAI v0.3.0 DALL-E 3目录遍历漏洞
CVE-2026-51904 SuperAGI≤v0.0.14越权漏洞
CVE-2026-51901 SuperAGI <=0.0.14 越权访问漏洞
CVE-2026-51898 pandas-ai 3.0.0 代码执行器存在代码注入漏洞
CVE-2026-51899 SuperAGI <0.0.14 存在水平权限漏洞
CVE-2026-51922 AgentScope v1.0.20 命令注入漏洞
CVE-2026-51916 TransformerOptimus SuperAGI v0.0.14 越权删除漏洞
CVE-2026-51918 FinRobot 1.0.0 CodingUtils.create_file_with_code() 代码注入漏洞
CVE-2026-51911 Vanna v2.0.2代码注入漏洞
CVE-2026-51917 FinRobot v1.0.0 CodingUtils模块代码注入漏洞
CVE-2026-51915 TransformerOptimus SuperAGI v0.0.14工具控制器越权漏洞
CVE-2026-51914 TransformerOptimus SuperAGI v0.0.14 存在错误访问控制漏洞
CVE-2026-67989 Ruby_llm Ruby 3.1.x ReDoS漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-51907

No comments yet


Leave a comment