Seroval 支持 JavaScript 值的字符串化,包括超越 JSON.stringify 能力范围的复杂结构。在 1.5.3 版本之前,seroval.fromJSON() 允许攻击者控制的 JSON Promise 控制节点,在未验证真实内部 Promise 解析器记录的情况下,对通用反序列化引用表中的值进行操作。当启用插件时,这会导致反序列化副作用;若下游框架注册了可调用包装器,则可能引发非预期的服务器端调用或远程代码执行。该问题已在 1.5.3 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet