Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Heym < 0.0.21 Sandbox Escape via Python Introspection
Vulnerability Description
Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated workflow authors to bypass sandbox restrictions by using object-graph introspection primitives. Attackers can use Python introspection techniques to recover the unrestricted __import__ function, import blocked modules such as os and subprocess, and access inherited backend environment variables containing database credentials and encryption keys to execute arbitrary host commands as the backend service user.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
保护机制失效
Vulnerability Title
Heym 安全漏洞
Vulnerability Description
Heym是heymrun开源的一个AI原生工作流自动化平台。 Heym 0.0.21之前版本存在安全漏洞,该漏洞源于自定义Python工具执行器中存在沙箱逃逸,可能导致经过身份验证的工作流作者通过对象图内省原语绕过沙箱限制。
CVSS Information
N/A
Vulnerability Type
N/A