Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Context7 2.1.2 Prompt Injection via Custom AI Instructions
Vulnerability Description
Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP server. Attackers can poison the custom instructions to exfiltrate credentials from environment files to an attacker-controlled service and perform destructive file deletion on the victim's machine when the agent makes a routine library documentation request.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
CWE-1427
Vulnerability Title
Upstash Context7 Platform 提示词注入漏洞
Vulnerability Description
Upstash Context7 Platform是Upstash组织的一个提供上下文信息整合与管理服务的平台。 Upstash Context7 Platform 存在提示词注入漏洞,可能导致攻击者利用漏洞破坏系统的机密性、完整性或可用性。
CVSS Information
N/A
Vulnerability Type
N/A