在 bsmi021 的 mcp-file-context-server 1.0.0 版本中检测到一个漏洞。该漏洞影响组件“路径解析”中 文件里的 函数。对参数 进行操作可导致路径穿越(path traversal)漏洞。攻击者可以远程发起攻击。利用方式现已公开,可能被用于攻击。该项目早已通过问题报告得知此问题,但尚未做出响应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| bsmi021 | mcp-file-context-server | 1.0.0 |
cpe:2.3:a:bsmi021:mcp-file-context-server:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet