漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
HelloGGX shadcn-vue-mcp callback-server.ts fs.promises.readFile path traversal
Vulnerability Description
A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by this issue is the function fs.promises.readFile of the file src/server/callback-server.ts. This manipulation of the argument filepath causes path traversal. The attack is restricted to local execution. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Sherlock Holmes Shadcn-vue MCP Server 路径遍历漏洞
Vulnerability Description
Sherlock Holmes Shadcn-vue MCP Server是Sherlock Holmes个人开发者开源的一款提供前端组件相关能力的模型上下文协议服务器。 Sherlock Holmes Shadcn-vue MCP Server e170e277b94235cde627803277fc8c41103a4d38及之前版本存在路径遍历漏洞,该漏洞源于src/server/callback-server.ts文件中的fs.promises.readFile函数对参数filepath的操作,容易
CVSS Information
N/A
Vulnerability Type
N/A