[高] 工作流引擎路径遍历漏洞 #74
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
问题描述
backend/app/services/workflow_engine.py 第2606行和2630行,文件操作节点未对用户传入的文件路径做校验,攻击者可使用 ../../../ 路径遍历攻击读取任意文件。
涉及文件
修复建议
严重程度
高 - 文件系统越权访问