已知 npm 包 版本 ≤ 0.29.1 的文档 API 中存在路径遍历(path traversal)漏洞。 具体而言, 中的 HTTP 处理器使用 对用户提供的文档路径进行规范化处理。该函数会去除路径首尾的斜杠以及 后缀,但并未消除 遍历序列。随后, 使用 构建目标路径,但没有验证解析后的路径是否仍位于文档目录内部。 在默认部署配置中,管理 API(Management API)是无认证的,且绑定到所有网络接口。因此,远程未认证攻击者可以构造包含路径遍历的负载(例如向 发送 ,或向 发送编码后的路径),从而在宿
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| knowns-dev | knowns | < 0.30.0 |
affected |
0.30.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| knowns-dev | knowns | 0 ~ 0.30.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet