Описание
5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Version 0.13.2 contains a vulnerability in the chat page's script gadgets that enables content injection attacks through multiple vectors: malicious prompt injection pages, compromised MCP servers, and exploited tool integrations. This is fixed in version 0.14.0.
Ссылки
- Release Notes
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:5ire:5ire:0.13.2:*:*:*:*:*:*:*
EPSS
Процентиль: 15%
0.00048
Низкий
9.6 Critical
CVSS3
Дефекты
CWE-79
EPSS
Процентиль: 15%
0.00048
Низкий
9.6 Critical
CVSS3
Дефекты
CWE-79