FaceFusion 3.6.1 及更早版本中的 函数未对任务标识符进行规范化处理,使得攻击者能够在“jobs”目录之外写入文件。攻击者可通过未认证的 HTTP API,在任务标识符参数中注入路径遍历序列(如 ),从而在系统上的任意位置创建文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| facefusion | facefusion | 0 ~ 3.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet