Chainlit 2.12.0 及更早版本未能验证客户端提供的 socket.io sessionId 参数,使得未认证的攻击者能够通过注入绝对路径或相对路径序列来实现文件系统路径穿越。攻击者可以构造恶意的 sessionId 值,从而逃逸出上传目录,并递归删除服务进程可访问的任意目录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet