LavaGue:网页内容经LLM处理后eval执行致RCE(#650)
Security Advisory
#650
Critical
LavaGue
Affected:
- LavaGue (all versions prior to the fix in PR #651)
- LavaGue with Python extraction engine (core/retractors.py, python_engine.py, action_engine.py)
Fixed in:
- Version containing PR #651 (fix: prevent code execution in Python extraction output)
Referenced CVEs:
CVE-2026-85694 · 8.1
文章内图片已隐藏以节省流量 · 升级 Pro 后可见图片及离线存档
本文由本平台从 github.com 自动抓取,经 LLM 流水线清洗、双语翻译。版权归原作者。查看原文。