Activepieces是Activepieces组织的一个可视化工作流自动化平台。 Activepieces 0.80.0之前版本存在命令注入漏洞,该漏洞源于代码编译管道从步骤名称构建磁盘路径并传递给shell调用的构建命令,步骤名称中的shell元字符可导致在创建代码沙箱前执行任意命令,可能导致经过身份验证的用户以worker进程用户身份执行命令、读写worker文件系统、泄露环境机密及访问内部服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| activepieces | activepieces | < 0.80.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| activepieces | activepieces | < 0.80.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73083 | 7.6 HIGH | Activepieces: V8 Isolate Sandbox Bypass via importFresh Module Loading |
| CVE-2026-73084 | 6.1 MEDIUM | Activepieces: Reflected Cross-Site Scripting in OAuth Redirect Endpoint |
| CVE-2026-73082 | 5.3 MEDIUM | Activepieces: Server-side request forgery in MCP tool validation endpoint |
No comments yet