@cgauge/yaml npm 软件包存在任意代码执行漏洞。攻击者可以通过嵌入自定义的 YAML 标签,在文档解析期间无条件地对攻击者提供的字符串值调用 ,从而执行任意 JavaScript 代码。使用该库解析不受信任的 YAML 输入的任何应用程序都将暴露完整的 Node.js 运行时权限,包括环境变量访问、文件系统读写、网络访问以及子进程执行,且不提供任何安全模式替代方案或退出机制。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cgauge | @cgauge/yaml | ≤ 0.27.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cgauge | @cgauge/yaml | 0 ~ 0.27.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: uid=0(root) gid=0(root) groups=0(root) | --- | PROOF_8047eb0e83c5e4fa
No comments yet