Vulnerabilities in labring

36 results
Vexday analysis

A Labring apresenta um panorama preocupante com 35 vulnerabilidades catalogadas, sendo 17 delas publicadas nos últimos 90 dias, o que indica um padrão recente de descobertas de segurança. Embora nenhuma esteja sob exploração ativa no momento, 7 vulnerabilidades críticas (CVSS elevado) foram identificadas, predominantemente relacionadas à injeção de solicitações HTTP lado do servidor (CWE-918), uma fração significativa do inventário de risco. A concentração em uma fraqueza específica e o ritmo acelerado de divulgações recentes sugerem necessidade de avaliação e correção prioritária nesta superfície de ataque.

CVE-2023-48225HIGHLaf env causes sensitive information disclosureEPSS 0.8%CVE-2023-50253CRITICALlaf logs leakEPSS 0.7%CVE-2026-42302CRITICALFastGPT: Unauthenticated Remote Code Execution (RCE) via code-server Misconfiguration in agent-sandboxEPSS 0.7%CVE-2023-33190CRITICALImproperly configured permissions in SealosEPSS 0.7%CVE-2026-40351CRITICALFastGPT: NoSQL Injection in loginByPassword leads to Authentication BypassEPSS 0.6%CVE-2023-36815HIGHSealos billing system permission control defectEPSS 0.5%CVE-2026-54607HIGHFastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the isInternalAddress guard)EPSS 0.5%CVE-2026-61684HIGHFastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default INVOKE_TOKEN_SECRET='token')EPSS 0.5%CVE-2026-55418HIGHFastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-team file disclosure)EPSS 0.5%CVE-2025-49131MEDIUMFastGPT Sandbox Vulnerable to Sandbox BypassEPSS 0.4%CVE-2026-34162CRITICALFastGPT: Unauthenticated SSRF via httpTools Endpoint Leads to Internal API Key TheftEPSS 0.4%CVE-2026-61644HIGHFastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant dataset text due to an unbound initialId lookupEPSS 0.4%CVE-2026-54601MEDIUMFastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant authorization confusionEPSS 0.4%CVE-2026-40352HIGHFastGPT: NoSQL Injection in updatePasswordByOld Leads to Account TakeoverEPSS 0.4%CVE-2026-61646MEDIUMFastGPT: Shared axios SSRF guard validates only the initial URL before following redirectsEPSS 0.4%CVE-2026-54602HIGHFastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getRecordEPSS 0.4%CVE-2026-40252MEDIUMBroken Access Control (IDOR) Leading to Cross-Tenant Application Access in FastGPTEPSS 0.3%CVE-2026-33075CRITICALFastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.ymlEPSS 0.3%CVE-2026-32128MEDIUMFastGPT Python Sandbox Bypass of File-Write RestrictionEPSS 0.3%CVE-2026-34163HIGHServer-Side Request Forgery via MCP Tools Endpoint in FastGPTEPSS 0.3%