目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-47763— PDM 后置链接漏洞

CVSS 6.8 · Medium EPSS 0.15% · P5

可能的 ATT&CK 技术 1AI

T1553 · Subvert Trust Controls

影响版本矩阵 1

厂商产品版本范围状态
pdm-projectpdm< 2.27.0affected
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2026-47763 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
pdm: Project-Local State and Config Writes Follow Symlinks
来源: CVE Program / CVE List V5
Vulnerability Description
pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes several project-local state or configuration files without symlink protection. If a malicious repository places those files as symlinks, local PDM operations can overwrite the symlink targets. This creates an arbitrary file clobber primitive relative to the privileges of the invoking user. Config.__init__() resolves the project-local pdm.toml path and _save_config() writes to the resolved target. If PROJECT_ROOT/pdm.toml is a symlink to another file, pdm config -l ... updates the target file instead of refusing the write. The same general problem exists for other project-local persistence paths that are written directly with no lstat / O_NOFOLLOW protection. For the pdm.toml PoC specifically, the target file must already contain parseable TOML. Otherwise the load step fails before the write path is reached. That parser constraint does not apply to the .pdm-python or .python-version sinks. This issue has been fixed in version 2.27.0.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
CWE-61
来源: CVE Program / CVE List V5
Vulnerability Title
PDM 后置链接漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
PDM是PDM组织的一款产品数据管理解决方案。 PDM 2.27.0之前版本存在后置链接漏洞,该漏洞源于写入项目本地状态或配置文件时未进行符号链接保护,可能导致恶意仓库通过符号链接覆盖任意文件。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
pdm-projectpdm < 2.27.0 -

二、漏洞 CVE-2026-47763 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-47763 的情报信息

登录查看更多情报信息。

CVE-2026-47763 厂商安全公告 (1)

CVE-2026-47763 厂商页面 (1)

同批安全公告 · pdm-project · 2026-08-04 · 共 3 条

CVE-2026-477648.4 HIGHPDM 路径遍历漏洞
CVE-2026-477818.4 HIGHPDM 软件供应链问题漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-47763

暂无评论


发表评论