在 ipa-lab 的 HackingBuddyGPT(版本 0.5.0 及以下)中发现了一个漏洞。该漏洞影响文件 中的 函数。该函数存在操作系统命令注入风险。攻击者可以通过网络远程发起攻击。该漏洞的利用方法已在公开资料中披露,且可能已被实际利用。项目方已通过问题报告较早获知此问题,但截至目前尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ipa-lab | HackingBuddyGPT | 0.1 |
cpe:2.3:a:ipa-lab:hackingbuddygpt:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet