PT-2026-24896 · Npm+2 · @Whyour/Qinglong+1
A7Cc
·
Publicado
2026-03-11
·
Atualizado
2026-05-01
·
CVE-2026-3965
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
whyour qinglong versions through 2.20.1
Description
A security issue has been identified in whyour qinglong. The problem resides in an unknown function within the
back/loaders/express.ts file of the API Interface component. Manipulation of the command argument can bypass a protection mechanism. This issue can be exploited remotely, and a public exploit is available.API Endpoint: Not specified.
Vulnerable Parameter:
commandRecommendations
Versions prior to 2.20.2 should be upgraded to version 2.20.2 to address this issue.
Exploit
Correção
Protection Mechanism Failure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
@Whyour/Qinglong
Qinglong