Mastra 1.63.0 及之前版本中,当配置中省略了 回调时,其内存 API 的线程所有权验证存在身份验证绕过漏洞。经过身份验证的攻击者可以通过 枚举所有线程,并读取其他资源所有者的对话历史记录和元数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet