MAA MAA是中国MAA公司的一款明日方舟游戏小助手。 MAA存在安全漏洞,该漏洞源于dev-v2工作流中的release-preparation.yml文件将攻击者控制的github.event.pull_request.title内联到run: shell命令中,导致标题以Release v开头的非草稿fork PR可在generate-changelog作业期间在ubuntu-latest运行器上执行shell命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MaaAssistantArknights | MaaAssistantArknights | < cafc3946059e6337d2089d4fec8b6885ba17c332 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MaaAssistantArknights | MaaAssistantArknights | < cafc3946059e6337d2089d4fec8b6885ba17c332 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet