在 cheshire-cat-ai(Cheshire Cat AI)版本 1.9.2 及更早版本中发现了一个漏洞。该漏洞位于文件 中的 函数。由于对参数 的操作处理不当,导致认证机制缺失。攻击者可远程发起攻击。该漏洞利用方式已公开披露,并可能被实际利用。项目组已通过问题报告较早获知此问题,但截至目前尚未作出回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cheshire-cat-ai | Cheshire Cat AI | 1.9.0 |
affected |
1.9.1 |
affected | ||
1.9.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cheshire-cat-ai | Cheshire Cat AI | 1.9.0 |
cpe:2.3:a:cheshire-cat-ai:cheshire_cat_ai:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet