TEN framework是TEN framework组织的一个支持多场景的开发框架。 TEN framework 0.11.71版本存在授权问题漏洞,该漏洞源于TMAN Designer file-content API端点缺乏身份验证导致任意文件读写,攻击者可向/api/designer/v1/file-content端点提交POST和PUT请求,读取任意文件或向系统路径写入恶意内容,从而通过authorized_keys、cron文件或可执行graph文件实现代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TEN-framework | ten-framework | ≤ 0.11.71 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TEN-framework | ten-framework | 0 ~ 0.11.71 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints, letting attackers read or write arbitrary files and execute code. The exploit requires no authentication. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-85688.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet