ModelScope ms-swift是ModelScope组织的一款深度神经网络模型训练微调框架。 ModelScope ms-swift 4.5.2版本存在服务端请求伪造漏洞,该漏洞源于swift deploy OpenAI-compatible API获取多模态媒体URL时未进行验证或重定向过滤,未经身份验证的攻击者可提供任意image_url、audio_url或video_url参数,使服务器向内部服务和云元数据端点发起请求。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| modelscope | ms-swift | ≤ 4.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| modelscope | ms-swift | 0 ~ 4.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet