Netron 版本 ≤9.1.2 的桌面应用程序中存在反射型跨站脚本(XSS)漏洞。由于节点名称未经过滤,攻击者可以利用该漏洞隐藏特定节点、执行端口扫描,或利用 Chrome 浏览器的“N-day”(已知但未打补丁的浏览器漏洞)来实现远程代码执行(RCE)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79719 | 6.8 MEDIUM | Netron<=9.1.2桌面应用反射型XSS导致RCE |
| CVE-2026-79718 | 6.8 MEDIUM | Netron≤9.1.2桌面版反射型XSS |
No comments yet