Perspective是Perspective团队的一款帮助用户从多维度视角审视与分析数据的辅助工具。 Perspective 5.0.0版本存在路径遍历漏洞,该漏洞源于路径处理不当,攻击者可在HTTP请求URL路径中包含../段,绕过不充分的查询字符串剥离清理,遍历到配置的资产根目录之外,读取服务器文件系统中的任意文件,如系统凭据和应用机密,且结果因通配符Access-Control-Allow-Origin头而跨域暴露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| perspective-dev | perspective | ≤ 5.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| perspective-dev | perspective | 0 ~ 5.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67195 | 8.8 HIGH | Perspective 5.0.0 RCE via eval() Expression Injection |
| CVE-2026-67198 | 7.5 HIGH | Perspective 5.0.0 DoS via VirtualServer Protocol Dispatcher |
| CVE-2026-67199 | 6.5 MEDIUM | Perspective 5.0.0 DoS via Loop Expression Evaluation |
| CVE-2026-67196 | 5.4 MEDIUM | Perspective 5.0.0 XSS via Debug Plugin innerHTML Interpolation |
No comments yet