当未配置认证密钥时,SGLang 在 端点允许未认证的 pickle 反序列化;由于内置的 和 均可被解析,SafeUnpickler 的安全策略可能被绕过,从而通过 pickle 的 REDUCE 操作实现代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet