TensorZero 是一个开源的 LLMOps(大语言模型运维)平台,统一提供了 LLM 网关、可观测性、评估、优化和实验等功能。在版本 2026.6.0 之前,TensorZero Gateway 的 端点接受由调用方提供的 JSON 参数,该参数会动态覆盖 配置。 当选择文件系统(filesystem)存储类型时,攻击者可以读取网关所在文件系统上的任意文件,包括凭证文件。当选择与 S3 兼容(s3_compatible)的存储类型时,会导致向攻击者指定的内部或云元数据端点发起出站对象存储请求。 该漏洞的利用需
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| tensorzero | tensorzero | < 2026.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tensorzero | tensorzero | < 2026.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet