Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command execution
Vulnerability Description
The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Tiny Humans OpenHuman 输入验证错误漏洞
Vulnerability Description
OpenHuman是Tiny Humans组织的一款个人 AI 超级智能。 Tiny Humans OpenHuman 0.54.0及之前版本存在安全漏洞,该漏洞源于安全策略中的shell工具命令允许列表存在缺陷,可能导致绕过限制执行任意OS命令。
CVSS Information
N/A
Vulnerability Type
N/A