Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

【SECURITY】 RCE 安全漏洞 #1526

Open
chenhbc opened this issue Nov 24, 2024 · 0 comments
Open

【SECURITY】 RCE 安全漏洞 #1526

chenhbc opened this issue Nov 24, 2024 · 0 comments
Labels
bug Something isn't working

Comments

@chenhbc
Copy link

chenhbc commented Nov 24, 2024

Bug 描述
创建爬虫页面中的执行命令可以输入任何命令,没有做安全限制,会导致 RCE(Remote Code Execution) 的安全问题。

期望结果
对该功能进行严格限制(前后端),仅能选择脚本类型和脚本路径。

截屏
image

@chenhbc chenhbc added the bug Something isn't working label Nov 24, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant