Process Compose 是非容器化应用的调度器与编排器。在 1.120.0 版本之前,位于 中的 MCP SSE 监听器接受发往 端点及返回的消息端点来自浏览器的请求,但未对 Host 头进行校验,未验证 Origin 头,也未对调用方进行身份认证。 当启用了 MCP SSE 功能时,恶意网站可利用 DNS 重绑定技术访问回环地址上的监听器,并发出 MCP 请求。如果同时启用了 选项,攻击者便可以枚举进程状态、读取或搜索日志、截断日志,以及对本地进程执行启动、停止、重启或扩缩容操作;此外,配置的用户自定义工
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| F1bonacc1 | process-compose | < 1.120.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| F1bonacc1 | process-compose | < 1.120.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet