gpt-crawler 在 1.5.1 及更早版本中,POST /crawl 端点对 参数缺乏有效验证,允许未经身份验证的攻击者向任意文件系统路径写入任意文件。攻击者可通过提供绝对路径或父目录片段(如 ),利用来自攻击者可控 URL 的内容,覆盖系统中已存在的文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| BuilderIO | gpt-crawler | ≤ 1.5.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| BuilderIO | gpt-crawler | 0 ~ 1.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet