Akana API 平台中发现了一个 XML 外部实体(XXE)漏洞,该漏洞源于在 XML 转 JSON 处理过程中,对外部实体引用的限制不当。此问题影响 Akana 2026.1、2025.1.1 版本,以及 2024.1.6 之前的所有版本(包括更早期已停止支持的版本)。该问题已在当前受支持版本的最新安全补丁中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet