LightLLM 1.2.0 及更早版本中存在一个远程代码执行漏洞,位于配置服务器(Config Server)中未进行身份验证的 WebSocket 端点。该端点直接将客户端发送的第一个数据帧传递给 进行反序列化。攻击者若能访问配置服务器端口,便可发送一个包含 方法的恶意序列化负载,从而以配置服务器进程的权限执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet