Yamcs 是一个任务控制框架。在 5.11.13 版本之前,Yamcs 的 StaticFileHandler.locateFile 方法在处理未认证的请求路径时,未使用 和 来验证绝对路径是否仍位于已配置的 目录内。如果路径中包含路径遍历(traversal)片段,攻击者可以逃逸出预期的 Web 根目录,从而返回服务器上任意可读文件的内容。该缺陷位于 文件中,可能导致敏感的操作系统和应用程序数据泄露。此问题已在 5.11.13 版本中修复,而 5.12 系列则从 5.12.0 版本起得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55565 | 9.9 CRITICAL | Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled |
| CVE-2026-55559 | 9.8 CRITICAL | Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance |
| CVE-2026-55511 | 9.1 CRITICAL | Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs ` |
| CVE-2026-55521 | 8.8 HIGH | Yamcs : Multiple Missing Function Level Access Control vulnerabilities in Yamcs Core API |
| CVE-2026-55545 | 6.5 MEDIUM | Yamcs: WebSocket subscription handlers omit the privilege checks their REST siblings enfor |
| CVE-2026-55549 | 6.5 MEDIUM | Yamcs: Reflected XSS in the URL of the Authorize Endpoint |
| CVE-2026-55547 | 4.3 MEDIUM | Yamcs: Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authen |
| CVE-2026-55566 | 4.3 MEDIUM | Yamcs: DOM XSS in Extension Routing |
No comments yet