Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
8421bit MiniClaw System kernel.ts resolveSkillScriptPath os command injection
Vulnerability Description
A vulnerability was detected in 8421bit MiniClaw 0.8.0/0.9.0. This issue affects the function resolveSkillScriptPath of the file src/kernel.ts of the component System Command Handler. The manipulation results in os command injection. The exploit is now public and may be used. The patch is identified as 223c16a1088e138838dcbd18cd65a37c35ac5a84. It is best practice to apply a patch to resolve this issue.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
MiniClaw 命令注入漏洞
Vulnerability Description
MiniClaw是8421bit个人开发者的一款AI的记忆与进化工具。 MiniClaw 0.8.0版本和0.9.0版本存在命令注入漏洞,该漏洞源于组件System Command Handler中文件src/kernel.ts的函数resolveSkillScriptPath存在OS命令注入。
CVSS Information
N/A
Vulnerability Type
N/A