Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
louisho5 picobot Workspace filesystem.go GetSkill link following
Vulnerability Description
A weakness has been identified in louisho5 picobot up to 0.2.0. Impacted is the function CreateSkill/GetSkill of the file internal/agent/tools/filesystem.go of the component Workspace Handler. Executing a manipulation can lead to link following. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Vulnerability Title
Louis Picobot 后置链接漏洞
Vulnerability Description
Louis Picobot是中国Louis个人开发者的一款自动化流程调度软件。 Louis Picobot 0.2.0版本及之前版本存在后置链接漏洞,该漏洞源于Workspace Handler组件中文件internal/agent/tools/filesystem.go的函数CreateSkill/GetSkill存在后置链接问题,可能导致远程攻击。
CVSS Information
N/A
Vulnerability Type
N/A