AutoAgent 存在一个未经身份验证的远程代码执行漏洞,位于其 TCP 服务器上。该服务器绑定到所有网络接口,并以 root 用户身份执行攻击者提供的命令。攻击者可以连接到暴露的通信端口,在容器内执行任意 bash 命令,从而获得对通过 bind mount 方式挂载的主机工作区目录的访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet