漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Context7 2.1.2 Prompt Injection via Custom AI Instructions
Vulnerability Description
Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP server. Attackers can poison the custom instructions to exfiltrate credentials from environment files to an attacker-controlled service and perform destructive file deletion on the victim's machine when the agent makes a routine library documentation request.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
CWE-1427
Vulnerability Title
Upstash Context7 Platform 提示词注入漏洞
Vulnerability Description
Upstash Context7 Platform是Upstash组织的一个提供上下文信息整合与管理服务的平台。 Upstash Context7 Platform 存在提示词注入漏洞,可能导致攻击者利用漏洞破坏系统的机密性、完整性或可用性。
CVSS Information
N/A
Vulnerability Type
N/A