Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Presenton < 0.8.8-beta - Authentication Bypass of Session Auth via Unprotected MCP Endpoint
Vulnerability Description
Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authentication (AUTH_USERNAME/AUTH_PASSWORD), is reachable unauthenticated at /mcp because the nginx front-end does not apply the auth_request gate to that path and the MCP server auto-mints a valid internal session token for the configured user. A remote unauthenticated attacker can invoke MCP tools such as generate_presentation, performing authenticated application actions, consuming the operators configured LLM API keys, and creating presentations in the operators instance. The Electron desktop build is not affected (MCP disabled).
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
Presenton 授权问题漏洞
Vulnerability Description
Presenton Presenton是Presenton公司开源的一款开源的 AI 演示文稿生成器,支持通过 API 集成或自托管,利用自定义模板快速生成可编辑的 PPTX/PDF 格式幻灯片,无供应商锁定。 Presenton 0.8.8-beta之前版本存在授权问题漏洞,该漏洞源于nginx前端未对/mcp路径应用auth_request网关且MCP服务器自动为配置用户生成有效内部会话令牌,导致远程未经验证攻击者可调用MCP工具(如generate_presentation),执行已认证应用操作,消
CVSS Information
N/A
Vulnerability Type
N/A