super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spliced into the command, resulting in a possible RCE vulnerability. Users should upgrade to super-xray 0.2-beta.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://github.com/4ra1n/super-xray/security/advisories/GHSA-732j-763p-cvqg | third party advisory exploit |
https://github.com/4ra1n/super-xray/releases/tag/0.2-beta | third party advisory release notes |