漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
PraisonAI before 4.6.78 Path Traversal via Custom Commands
Vulnerability Description
PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute paths in project command files to exfiltrate process-readable files into model prompts.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Mervin Praison PraisonAI 路径遍历漏洞
Vulnerability Description
Mervin Praison PraisonAI是Mervin Praison个人开发者开源的一个低代码多智能体协作框架。 Mervin Praison PraisonAI 4.6.78之前版本存在路径遍历漏洞,该漏洞源于无法验证自定义命令模板中的文件路径引用,可能允许攻击者读取工作区之外的文件。攻击者可以在项目命令文件中包含路径遍历序列(如@../outside_secret.txt)或绝对路径,将进程可读文件泄露到模型提示中。
CVSS Information
N/A
Vulnerability Type
N/A