BISHENG 在 2.6.0 版本之前存在一个远程代码执行(RCE)漏洞,位于工作流的 接口中,允许经过身份验证的用户执行任意 Python 代码。攻击者可以通过向 接口提交精心构造的 Code 节点定义,这些代码在未经沙箱隔离的情况下通过 函数直接执行,从而使攻击者能够访问文件系统、凭证以及内部网络资源。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dataelement | bisheng | < 2.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dataelement | bisheng | 0 ~ 2.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet