在 0717376 cowork_bench 项目中(版本直至 d943e75bc0fc8e3b27141979300cd8cbcd1e890d)发现一个漏洞。受影响的组件是 pdf-tools-mcp,具体位于文件 中的 函数。通过恶意操纵参数 ,可触发服务器端请求伪造(SSRF)漏洞。该攻击可远程发起,且利用方法已公开,可能被用于实际攻击。 该产品采用滚动发布(rolling release)模式以实现持续交付,因此无法提供受影响的或已修复的具体版本信息。项目维护方已通过问题报告提前获知此问题,但截至目前尚未作
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 0717376 | cowork_bench | d943e75bc0fc8e3b27141979300cd8cbcd1e890d |
cpe:2.3:a:0717376:cowork_bench:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet