LightLLM 1.2.0 及更早版本中存在一个身份验证绕过漏洞,位于 WebSocket 端点。未经身份验证的攻击者可以通过提供精心构造的 JSON 数据(且无需进行对端地址验证)来注册任意节点。攻击者可以利用该漏洞: 1. 获取被路由到其 socket 的完整用户提示词(prompts); 2. 通过替换合法节点引发拒绝服务(DoS); 3. 诱导 PD Master 向内部网络地址发起请求,从而可能进一步攻击内部网络。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet