ash-project 的 igniter 中存在“转义、元字符或控制序列未正确中和”的漏洞,恶意包发布者借此伪造 的确认提示。 在添加包之前会打印一个确认面板(一种防止拼写仿冒的安全机制),列出该包的十六进制元数据。Igniter.Project.Deps 中的面板构建器在将发布者可控的字段( 、所有者用户名、依赖项名称、版本号)写入终端时,仅去除了换行符。恶意或拼写仿冒的包可以在其元数据中嵌入 ANSI 终端转义序列(光标移动、清行、回车等),从而覆盖面板内容:伪造可信的作者名和下载量,同时隐藏真实信息。依赖该
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | igniter | 0.8.1 ~ 0.8.4 |
cpe:2.3:a:ash-project:igniter:*:*:*:*:*:*:*:*
|
|
| ash-project | igniter | d26d9b3a8348661813617606076315075d32663b ~ d492b1aa33f8fb0dacc0afa41b703fb922d42816 |
cpe:2.3:a:ash-project:igniter:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82753 | 8.2 HIGH | Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and c |
| CVE-2026-82586 | 8.2 HIGH | AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private at |
| CVE-2026-82755 | 6.3 MEDIUM | ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheab |
| CVE-2026-82758 | 6.3 MEDIUM | ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gat |
| CVE-2026-82754 | 6.3 MEDIUM | ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypas |
| CVE-2026-82757 | 6.3 MEDIUM | ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addre |
| CVE-2026-82756 | 6.3 MEDIUM | ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenti |
| CVE-2026-81638 | 2.1 LOW | Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry |
No comments yet