### 漏洞概述 **漏洞名称**: Privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold (missing self-rights constraint, sibling of the updateUserRights fix) …
### 漏洞概述 **标题**: [Security] Approval hook cwd symlink race allows exec to run in a different directory than the approved one #3081 **描述**: Picoclaw的审批流程中,`exec`工具未将审查的工作目录身份绑定到最终用于进程执行的目录。攻击者可以影响`cwd`…