BeamMCP.Schema 中存在不正确的输入验证漏洞。在 ScriptKittyOS 的 beam_mcp 中,该漏洞允许 MCP 客户端使用违反服务器所声明输入架构参数的值,来调用工具的分发函数。BeamMCP.Schema.validate/2 仅对顶层参数对象检查了类型(type)、必需字段(required)、额外属性(additionalProperties)、枚举值(enum)以及数值范围限制。然而,工具通过 tools/list 声明的那些嵌套对象内部的约束条件以及数组项的约束(如 items、m
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ScriptKittyOS | beam_mcp | 0.1.0 ~ 0.10.1 |
cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:*
|
|
| ScriptKittyOS | beam_mcp | 083838eb8e17fe5f6fcaf761bdbe203110288b0b ~ 289dbdbad641943b29a3b8d1eb36506cc8cec10a |
cpe:2.3:a:scriptkittyos:beam_mcp:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet