在 sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1 中发现了一个漏洞。该漏洞影响组件“Tool Handler”中文件 src/tools/handlers.ts 的 handleToolCall 函数。对参数格式的操作会导致操作系统命令注入(OS Command Injection)。攻击者需要具备本地访问权限才能实施攻击。目前该漏洞的利用方法已公开,可能被恶意利用。项目方已通过问题报告早期获知此漏洞,但截至目前尚未作出回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| sworddut | mcp-ffmpeg-helper | 0.1.0 |
affected |
0.1.1 |
affected | ||
0.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sworddut | mcp-ffmpeg-helper | 0.1.0 |
cpe:2.3:a:sworddut:mcp-ffmpeg-helper:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet