Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-2129 PoC — Mage AI 安全漏洞

Source
Associated Vulnerability
Title:Mage AI 安全漏洞 (CVE-2025-2129)
Description:Mage AI是Mage开源的一个构建、运行和管理数据管道的智能程序。 Mage AI 0.9.75版本存在安全漏洞,该漏洞源于资源初始化不安全。
Description
A vulnerability was found in Mage AI 0.9.75. It has been classified as problematic. This affects an unknown part. The manipulation leads to insecure default initialization of resource. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. After 7 months of repeated follow-ups by the researcher, Mage AI has decided to not accept this issue as a valid security vulnerability and has confirmed that they will not be addressing it.
File Snapshot

id: CVE-2025-2129 info: name: Mage AI - Insecure Default Authentication Setup author: zn9988,H0 ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.