在 the-momentum open-wearables(截至版本 0.6.2)中发现了一个漏洞。该漏洞影响组件“公共邀请码兑换端点”(Public Invitation-Code Redemption Endpoint)中文件 backend/app/api/routes/v1/user_invitation_code.py 的 redeem_invitation_code 函数。通过对参数 code 的操纵,可导致身份验证缺失。远程攻击者可利用此漏洞进行攻击。项目方已通过问题报告提前获知该问题,但至今尚未作出
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.