在 iswalle getnote-mcp 版本 1.5.0 及以下版本中检测到一个漏洞。受影响的是组件 中文件 的 函数。对参数 进行操纵会导致路径遍历(Path Traversal)漏洞。该攻击可远程发起。利用方式现已公开,可能被攻击者使用。升级到版本 1.5.1 即可修复此问题。对应的补丁名为 。建议升级受影响的组件以消除该漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| iswalle | getnote-mcp | 1.0 |
cpe:2.3:a:iswalle:getnote-mcp:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet