在 MAA-AI 的 MaaMCP(版本 1.1.1.dev6+g2e4a41287 及更早版本)中发现了一个漏洞。受影响的组件是文件 中的 / 函数。通过执行特定操作可触发路径遍历(path traversal)漏洞。该攻击可远程发起,且利用代码已公开,存在被利用的风险。修复补丁编号为 c93ef45cba75295eba26d9ff1ffb9202a91c6150。建议部署该补丁以修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet