工具被文档描述为只读 Ruby 沙箱,并通过一个基于模式的拒绝列表(denylist)以及对 进程中方法(如进程创建方法)的替换来进行强制约束。然而,伪终端(pseudo-terminal)库的 入口点既不在拒绝列表中,也未被替换。因此,一次普通的工具调用可以触达这些入口点,从而启动 shell,并以运行服务器的账户身份执行命令,且这些操作发生在受保护方法之外。 该拒绝列表自 1.4.0 版本随工具一起引入,但直至 1.6.0 版本都未涵盖上述入口点。在 1.6.1 版本中,沙箱所允许的 语句被限制为纯数据列表,并
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| maquina-app | rails-mcp-server | 1.4.0≤ 1.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| maquina-app | rails-mcp-server | 1.4.0 ~ 1.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet