脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
RCE via Prompt Injection Into Cursor's Terminal Cmd-K
脆弱性説明
Cursor is a code editor built for programming with AI. Prior to Sep 27, 2024, if a user generated a terminal command via Cursor's Terminal Cmd-K/Ctrl-K feature and if the user explicitly imported a malicious web page into the Terminal Cmd-K prompt, an attacker with control over the referenced web page could have a significant chance of influencing a language model to output arbitrary commands for execution in the user's terminal. This scenario would require the user explicitly opt-in to including the contents of a compromised webpage, and it would require that the attacker display prompt injection text in the the contents of the compromised webpage. A server-side patch to not stream back newlines or control characters was released on September 27, 2024, within two hours of the issue being reported. Additionally, Cursor 0.42 includes client-side mitigations to prevent any newline or control character from being streamed into the terminal directly. It also contains a new setting, `"cursor.terminal.usePreviewBox"`, which, if set to true, streams the response into a preview box whose contents then have to be manually accepted before being inserted into the terminal. This setting is useful if you're working in a shell environment where commands can be executed without pressing enter or any control character. The patch has been applied server-side, so no additional action is needed, even on older versions of Cursor. Separately, Cursor's maintainers also recommend, as best practice, to only include trusted pieces of context in prompts.
CVSS情報
N/A
脆弱性タイプ
输入验证不恰当
脆弱性タイトル
Cursor 输入验证错误漏洞
脆弱性説明
Cursor是Cursor开源的一个 AI 代码编辑器。 Cursor 20240927之前版本存在输入验证错误漏洞,该漏洞源于如果用户通过Cursor的终端Cmd-K/Ctrl-K功能生成终端命令,攻击者很有可能影响语言模型以输出任意命令在用户的终端中执行。
CVSS情報
N/A
脆弱性タイプ
N/A