PT-2026-24896 · Npm+2 · @Whyour/Qinglong+1

A7Cc

·

Publicado

2026-03-11

·

Atualizado

2026-05-01

·

CVE-2026-3965

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions whyour qinglong versions through 2.20.1
Description A security issue has been identified in whyour qinglong. The problem resides in an unknown function within the back/loaders/express.ts file of the API Interface component. Manipulation of the command argument can bypass a protection mechanism. This issue can be exploited remotely, and a public exploit is available.
API Endpoint: Not specified. Vulnerable Parameter: command
Recommendations Versions prior to 2.20.2 should be upgraded to version 2.20.2 to address this issue.

Exploit

Correção

Protection Mechanism Failure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3965
GHSA-XJ37-QJG2-XWV2

Produtos afetados

@Whyour/Qinglong
Qinglong