以下是该漏洞描述的中文翻译: Ash Project 的 ash_ai 中存在“源验证错误”漏洞 Ash Project 中的 存在源验证错误漏洞,允许恶意网页绕过 MCP 服务器的 DNS 重绑定(DNS-rebinding)防护机制,从而以用户的身份向用户的本地 MCP 服务器发起跨站点请求。 技术细节: 在 中,当 默认为 时, 函数在满足以下条件时会接受该源(origin): 1. ; 2. 转发的协议(forwarded scheme)为 。 这两个值均可被攻击者控制: 来自 HTTP 头; 协议(sch
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash_ai | 0.8.0 ~ 1.0.0 |
cpe:2.3:a:ash-project:ash_ai:*:*:*:*:*:*:*:*
|
|
| ash-project | ash_ai | c94f0b17fbe252f68755ba512678586164ba6139 ~ 28af68d73134df0b8fb3aa6ab03e8fd795b07c21 |
cpe:2.3:a:ash-project:ash_ai:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet