Skyvern 1.0.45 之前版本中存在一个沙箱逃逸漏洞,位于 TextPromptBlock 中。该漏洞源于提示词(prompt)被渲染两次:首先通过一个沙箱化的 Jinja 环境进行渲染,随后又通过一个未沙箱化的环境进行第二次渲染。攻击者可以通过工作流参数或上游区块的输出注入恶意的 Jinja 模板语法,从而以服务器进程的权限执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Skyvern-AI | skyvern | 0.2.1 ~ 1.0.45 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet