漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
andreahaku llm_memory_mcp GitHooksManager.ts auto.capture command injection
Vulnerability Description
A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of the file src/autolearn/GitHooksManager.ts of the component llm_memory_mcp. Executing a manipulation of the argument hash can lead to command injection. The attack is restricted to local execution. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
andreahaku llm memory mcp 输入验证错误漏洞
Vulnerability Description
andreahaku llm memory mcp是andreahaku个人开发者的一款为大型语言模型提供记忆管理功能的MCP服务器。 andreahaku llm memory mcp f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0及之前版本存在安全漏洞,该漏洞源于src/autolearn/GitHooksManager.ts文件auto.capture函数中参数hash的操作,可能导致命令注入,攻击仅限本地执行。
CVSS Information
N/A
Vulnerability Type
N/A