在 00Kisumi00 的 mcp-file-analyzer 工具中(版本直至提交哈希 f0cf0cf5db4781b1ca6d7c6a6d210405)发现了一个安全缺陷。该漏洞影响 analyze_csv_data MCP 组件中 main.py 文件内的 ControlFlowNode 函数。攻击者通过操纵参数 filename 可实现路径遍历(Path Traversal)漏洞。该攻击可被远程利用。该漏洞的利用方式已在公开渠道披露,可被用于发起攻击。由于该产品采用滚动发布(rolling release
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 00Kisumi00 | mcp-file-analyzer | 84740852f0cf0cf5db4781b1ca6d7c6a6d210405 |
cpe:2.3:a:00kisumi00:mcp-file-analyzer:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet