Описание
knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.
Ссылки
EPSS
Процентиль: 19%
0.00268
Низкий
8.3 High
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 8.3
github
13 дней назад
knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.
EPSS
Процентиль: 19%
0.00268
Низкий
8.3 High
CVSS3
Дефекты
CWE-863