OliveTin是OliveTin团队开源的一个Web应用。 OliveTin 3000.0.0版本至3000.17.0之前版本存在资源管理错误漏洞,该漏洞源于OAuth2登录处理器在每次/oauth/login请求时存储每个登录状态于registeredStates映射中,未过期、删除或限制条目,导致未经过身份验证的攻击者耗尽内存并造成拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-67438 | 6.6 MEDIUM | OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check |
| CVE-2026-67439 | 4.3 MEDIUM | OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output |
No comments yet