Chatbot 界面存在一个授权绕过漏洞,位于检索端点中,允许经过身份验证的攻击者通过提供任意文件 UUID 来访问其他用户的私有文件内容。该端点使用基于服务角色的 Supabase 客户端,该客户端绕过了行级安全策略,且未对文件所有权进行验证,从而允许攻击者通过精心构造的 POST 请求,从受害者的文件中检索出已索引的内容块。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mckaywrigley | chatbot-ui | ≤ 81328b61d2a4ab597a7a057be70e785cf756d9f8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mckaywrigley | chatbot-ui | 0 ~ 81328b61d2a4ab597a7a057be70e785cf756d9f8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet