SadTalker 在视频复混(muxing)流程中存在操作系统命令注入漏洞:上传的音频文件名未经过充分转义,直接被插入到 ffmpeg 命令行中。攻击者可通过上传文件名中带有 shell 元字符(如 、 、 等)的音频文件,使其在视频生成过程中“跳出”引号边界,从而执行任意系统命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenTalker | SadTalker | ≤ 0.0.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenTalker | SadTalker | 0 ~ 0.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet