漏洞标题
开放型 BMB XAgent 特权模式沙箱
漏洞描述信息
发现OpenBMB XAgent 1.0.0中的一个漏洞。它已被宣布为关键性漏洞。受此漏洞影响的是Privileged Mode组件的未知功能。该操作会导致沙箱问题。攻击需要本地进行。exploit已公开披露,可能被利用。此漏洞的标识符为VDB-255265。
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
漏洞类别
将资源暴露给错误范围
漏洞标题
OpenBMB XAgent Privileged Mode sandbox
漏洞描述信息
A vulnerability was found in OpenBMB XAgent 1.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Privileged Mode. The manipulation leads to sandbox issue. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier VDB-255265 was assigned to this vulnerability.
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
漏洞类别
权限/沙箱问题
漏洞标题
OpenBMB XAgent 安全漏洞
漏洞描述信息
XAgent是OpenBMB开源的一个开源的实验性大型语言模型(LLM)驱动的自治代理。 OpenBMB XAgent 1.0.0版本存在安全漏洞,该漏洞源于组件Privileged Mode会导致沙箱问题。
CVSS信息
N/A
漏洞类别
其他