在 0215AndrewFeng ACE-MCP 4.10.8 及更早版本中已发现一个安全漏洞。受影响组件为 MCP Tool,具体涉及 文件中的 函数。攻击者可通过操纵 和 参数触发路径遍历(Path Traversal)漏洞。该漏洞可被远程利用。目前,该漏洞的利用代码已公开,可被用于实施攻击。 现有防护机制 仅限制 不能超出攻击者所选的 范围;然而, 本身是未经信任的客户端输入。例如,若将 设置为 ,并将 设置为 ,即可绕过该检查。项目方虽已通过问题报告早期得知此漏洞,但截至目前仍未作出回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| 0215AndrewFeng | ACE-MCP | 4.10.0 |
affected |
4.10.1 |
affected | ||
4.10.2 |
affected | ||
4.10.3 |
affected | ||
4.10.4 |
affected | ||
4.10.5 |
affected | ||
4.10.6 |
affected | ||
4.10.7 |
affected | ||
| … +1 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 0215AndrewFeng | ACE-MCP | 4.10.0 |
cpe:2.3:a:0215andrewfeng:ace-mcp:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet