OSV 1.4.0 · unreviewed · 修改于 2026-09-01 23:31
发布时间
2026-09-01 05:32
GitHub 审查时间
—
NVD 发布时间
2026-09-01 05:17
源文件
advisories/unreviewed/2026/08/GHSA-2p3m-whr7-9m4w/GHSA-2p3m-whr7-9m4w.json
A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value used by set_file_name() and load_meta_data() in metagpt/ext/spo/utils/load.py. The vulnerable code joins the attacker-controlled FILE_NAME value with the settings directory and opens the resulting path without validating that the resolved path remains within the intended directory.
该公告没有提供结构化的受影响软件包信息。