Описание
5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. In versions 0.15.2 and prior, an RCE vulnerability exists in useMarkdown.ts, where the markdown-it-mermaid plugin is initialized with securityLevel: 'loose'. This configuration explicitly permits the rendering of HTML tags within Mermaid diagram nodes. This issue has not been patched at time of publication.
Ссылки
- Product
- Release Notes
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.15.2 (исключая)
cpe:2.3:a:5ire:5ire:*:*:*:*:*:*:*:*
EPSS
Процентиль: 14%
0.00045
Низкий
9.6 Critical
CVSS3
Дефекты
CWE-79
EPSS
Процентиль: 14%
0.00045
Низкий
9.6 Critical
CVSS3
Дефекты
CWE-79