Rust 中的 arrayref 0.3.10 库在编译使用它的代码时会执行恶意代码。原因该库存在一个恶意依赖项,该依赖项会连接到命令与控制服务器,从而实现任意代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-77650 | 9.8 CRITICAL | Rust append-only-vec 0.1.9依赖注入致远程代码执行 |
| CVE-2026-77649 | 9.8 CRITICAL | Internment crate 0.8.7 Rust远程代码执行漏洞 |
No comments yet