漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool
Vulnerability Description
FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a non-configurable, non-writable own property, the ECMAScript Proxy invariants force the security membrane to hand back the raw host object, letting a script reach _zod.constr.constructor (the host Function constructor) and execute arbitrary code in the server process. A single tools/call is sufficient to escape the sandbox and achieve remote code execution as the server user, exposing everything the process holds such as OAuth client secrets, JWT_SECRET, session keys, database credentials, and cloud instance metadata. Because the framework's DEFAULT_AUTH_OPTIONS is public mode, an unconfigured server serves this to unauthenticated callers, and on authenticated servers an indirect prompt injection in tool output or fetched content can trigger it without a human attackerThis issue is fixed in version 1.5.7.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
AgentFront FrontMCP 代码注入漏洞
Vulnerability Description
AgentFront FrontMCP是AgentFront组织开源的一个基于TypeScript的MCP服务器开发框架。 AgentFront FrontMCP 1.5.7之前版本存在代码注入漏洞,该漏洞源于沙箱化codecall:execute工具暴露了宿主Zod模式实例,导致脚本可访问_zod.constr.constructor并执行任意代码,可能导致远程代码执行及敏感信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A