漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
NousResearch hermes-agent file_tools.py _check_sensitive_path symlink
Vulnerability Description
A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path of the file tools/file_tools.py. The manipulation results in symlink following. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.9.0 is able to mitigate this issue. The patch is identified as 311dac197145e19e07df68feba2cd55d896a3cd1. Upgrading the affected component is recommended.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
CWE-61
Vulnerability Title
Hermes Agent 后置链接漏洞
Vulnerability Description
Hermes Agent是Nous Research开源的一款具备自我学习循环的AI代理工具。 Hermes Agent 0.8.0版本存在后置链接漏洞,该漏洞源于文件tools/file_tools.py中函数_check_sensitive_path操作不当,可能导致符号链接跟随。
CVSS Information
N/A
Vulnerability Type
N/A