ToolUniverse 在一个沙箱中运行调用方提供的 Python 代码,但该沙箱可被逃逸,而运行它的服务器并未要求任何身份验证。位于 中、 工具背后的执行器会检查提交源码中是否包含被禁止的属性名称和调用,但保留了通过字符串查找可达到的双下划线(dunder)属性,也未能阻止通过已允许的模块访问双下划线属性。因此,调用方可以从某个字面量的类出发,向其基类遍历并枚举子类,从而获取到 和 模块的引用。此外,一个按次调用的参数还允许调用方在检查运行之前扩大导入允许列表。 和 中的 HTTP 和 MCP 服务器绑定到所有
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mims-harvard | ToolUniverse | ≤ 1.2.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mims-harvard | ToolUniverse | 0 ~ 1.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet