漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Vanna 2.0.2 Path Traversal via FileSystemConversationStore
Vulnerability Description
Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write attacker-controlled JSON files to arbitrary filesystem locations and read conversation metadata from outside the intended store base directory. Attackers can supply path traversal sequences in the conversation_id parameter submitted to the unauthenticated chat API endpoints to escape the base directory during both write and read operations, enabling arbitrary file write with attacker-controlled content and unauthorized file read on the server filesystem.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Vanna 路径遍历漏洞
Vulnerability Description
Vanna是安圭拉Vanna公司开源的一个个性化 AI SQL 代理。 Vanna 2.0.2及之前版本存在路径遍历漏洞,该漏洞源于FileSystemConversationStore持久化集成存在路径遍历问题,可能导致未经验证的远程攻击者在conversation_id参数中提供路径遍历序列,从而在服务器文件系统上写入攻击者控制的JSON文件,并读取预期存储基目录之外的对话元数据。
CVSS Information
N/A
Vulnerability Type
N/A