Schwachstellenklasse
An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.
Quellen
- https://github.com/23blocks-OS/ai-maestro/commit/06d54f0687ad1fc5898a688a92f7e1f2df56c475
- https://github.com/23blocks-OS/ai-maestro/security/advisories/GHSA-mf7j-vfrr-jmfh
- https://github.com/rajukani100/CVE-research/tree/main/ai-maestro-rce-advisory
- https://github.com/rajukani100/CVE-research/tree/main/ai-maestro-rce-advisory
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.