Quivr 在 0.0.322 及更早版本中,提示词(prompt)端点未对所有权进行有效验证,导致经过身份验证的用户可以通过标识符修改任意提示词。拥有共享“brain”(知识库/工作区)只读权限的攻击者,可以读取已暴露的提示词标识符,并覆盖系统提示词,从而影响所有使用该 brain 的用户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet