漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Vulnerability Description
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinement, allowing attacker-controlled response bytes to be written to arbitrary filesystem paths the process can access. This issue is fixed in version 2.26.6.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Flyto2 Core 路径遍历漏洞
Vulnerability Description
Flyto2 Core是Flyto2组织的一个服务器与网络设备核心平台。 Flyto2 Core 2.26.6之前版本存在安全漏洞,该漏洞源于image.download和相关的写入文件模块使用调用者控制的output_dir而未使用validate_path_with_env_config和FLYTO_SANDBOX_DIR限制,允许攻击者控制的响应字节写入任意文件系统路径。
CVSS Information
N/A
Vulnerability Type
N/A