AI Agent Automation 是一个模块化的 AI 智能体工作流自动化平台,具备调度器、工具集和可观测性能力。在 0.9.1 版本之前,后端文件 中的 文件步骤实现存在安全漏洞:该实现将用户可控的 值通过 函数与 (当前工作目录)结合处理后,直接用于执行读取或写入操作,而未验证解析后的路径是否仍位于允许的工作流目录范围内。 因此,任何已认证且能够创建或修改工作流文件步骤的用户,均可通过注入路径遍历片段(如 )逃逸出预期的工作空间,进而读取敏感文件,或在后端进程拥有相应权限的情况下,写入或覆盖可访问的文件,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vmDeshpande | ai-agent-automation | < 0.9.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet