ash-project 的 ash_ai 中存在代码生成控制不当(代码注入)漏洞,允许远程、未认证的客户机执行任意 Elixir 代码。 通过 评估提示(prompt)内容。文档中记载的 形式的提示,其内容可依据动作参数构建。因此,当提示动作的文本中包含了来自请求的数据时,这些由攻击者控制的文本会被编译并作为 EEx 模板(Elixir 源码)执行。类似 的内容会在向模型发起请求之前就在服务器上执行,且只需访问提示动作即可触发,无需身份验证。该修复措施停止将函数提供的提示内容作为 EEx 进行评估;只有静态配置的模
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash_ai | 0.1.0 ~ 1.0.0 |
cpe:2.3:a:ash-project:ash_ai:*:*:*:*:*:*:*:*
|
|
| ash-project | ash_ai | 4aab131d40a0bd5a8cf0b3c4eaaa59d49565f3d1 ~ e9948254b5659c1143b73dc2f59f457931e64514 |
cpe:2.3:a:ash-project:ash_ai:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet