Vulnerabilidades em labring
35 resultadosAnálise Vexday
A Labring apresenta um panorama preocupante com 35 vulnerabilidades catalogadas, sendo 17 delas publicadas nos últimos 90 dias, o que indica um padrão recente de descobertas de segurança. Embora nenhuma esteja sob exploração ativa no momento, 7 vulnerabilidades críticas (CVSS elevado) foram identificadas, predominantemente relacionadas à injeção de solicitações HTTP lado do servidor (CWE-918), uma fração significativa do inventário de risco. A concentração em uma fraqueza específica e o ritmo acelerado de divulgações recentes sugerem necessidade de avaliação e correção prioritária nesta superfície de ataque.
CVE-2023-48225HIGHLaf env causes sensitive information disclosureEPSS 0.8%CVE-2023-50253CRITICALlaf logs leakEPSS 0.7%CVE-2026-42302CRITICALFastGPT: Unauthenticated Remote Code Execution (RCE) via code-server Misconfiguration in agent-sandboxEPSS 0.7%CVE-2023-33190CRITICALImproperly configured permissions in SealosEPSS 0.7%CVE-2026-40351CRITICALFastGPT: NoSQL Injection in loginByPassword leads to Authentication BypassEPSS 0.6%CVE-2023-36815HIGHSealos billing system permission control defectEPSS 0.5%CVE-2026-34162CRITICALFastGPT: Unauthenticated SSRF via httpTools Endpoint Leads to Internal API Key TheftEPSS 0.4%CVE-2026-40352HIGHFastGPT: NoSQL Injection in updatePasswordByOld Leads to Account TakeoverEPSS 0.4%CVE-2025-49131MEDIUMFastGPT Sandbox Vulnerable to Sandbox BypassEPSS 0.4%CVE-2026-40252MEDIUMBroken Access Control (IDOR) Leading to Cross-Tenant Application Access in FastGPTEPSS 0.3%CVE-2026-55418HIGHFastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-team file disclosure)EPSS 0.3%CVE-2026-33075CRITICALFastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.ymlEPSS 0.3%CVE-2026-32128MEDIUMFastGPT Python Sandbox Bypass of File-Write RestrictionEPSS 0.3%CVE-2026-61684HIGHFastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default INVOKE_TOKEN_SECRET='token')EPSS 0.3%CVE-2026-34163HIGHServer-Side Request Forgery via MCP Tools Endpoint in FastGPTEPSS 0.3%CVE-2026-42343MEDIUMFastGPT: Uncontrolled Resource Consumption leading to Sandbox ExhaustionEPSS 0.3%CVE-2026-44285HIGHFastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview APIEPSS 0.3%CVE-2025-27600MEDIUMFastGPT SSRFEPSS 0.3%CVE-2026-40100MEDIUMFastGPT has Unauthenticated SSRF in /api/core/app/mcpTools/runTool via missing CHECK_INTERNAL_IP defaultEPSS 0.3%CVE-2026-61646MEDIUMFastGPT: Shared axios SSRF guard validates only the initial URL before following redirectsEPSS 0.2%