漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
NousResearch hermes-agent WeChat Work Platform Adapter wecom.py path traversal
Vulnerability Description
A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component WeChat Work Platform Adapter. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Hermes Agent 路径遍历漏洞
Vulnerability Description
Hermes Agent是Nous Research开源的一款具备自我学习循环的AI代理工具。 Hermes Agent 0.8.0版本存在路径遍历漏洞,该漏洞源于文件gateway/platforms/wecom.py中未知功能操作不当,可能导致路径遍历。
CVSS Information
N/A
Vulnerability Type
N/A