目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1000

100.0%

CVE-2025-2129 PoC — Mage AI 安全漏洞

来源
关联漏洞
标题:Mage AI 安全漏洞 (CVE-2025-2129)
Description:Mage AI是Mage开源的一个构建、运行和管理数据管道的智能程序。 Mage AI 0.9.75版本存在安全漏洞,该漏洞源于资源初始化不安全。
Description
A vulnerability was found in Mage AI 0.9.75. It has been classified as problematic. This affects an unknown part. The manipulation leads to insecure default initialization of resource. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. After 7 months of repeated follow-ups by the researcher, Mage AI has decided to not accept this issue as a valid security vulnerability and has confirmed that they will not be addressing it.
文件快照

id: CVE-2025-2129 info: name: Mage AI - Insecure Default Authentication Setup author: zn9988,H0 ...
神龙机器人已为您缓存
备注
    1. 建议优先通过来源进行访问。
    2. 如果因为来源失效或无法访问,请发送邮件到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
    3. 神龙已为您对 POC 代码进行快照,为了长期维护,请考虑为本地 POC 付费/捐赠,感谢您的支持。