从版本 0.1.61 及以下的 appium-mcp-server 存在安全漏洞:其 和 工具未能对文件路径进行验证或规范化处理,允许攻击者将文件写入到预期的 目录之外。攻击者可以通过提供绝对路径或包含父目录段(如 )的相对路径,以服务器用户的权限覆盖任意文件,例如用户主目录中的 shell 配置文件和配置项。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| argneshu | appium-mcp-server | ≤ 0.1.61 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| argneshu | appium-mcp-server | 0 ~ 0.1.61 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet