References https://github.com/serverless/serverless/security/advisories/GHSA-rwc2-f344-q6w6 https://nvd.nist.gov/vuln/detail/CVE-2025-69256 https://www.sentinelone.com/vulnerability-database/cve-2025-69256/ https://github.com/advisories/GHSA-rwc2-f344-q6w6 https://www.geordie.ai/resources/technical-advisory-serverless-framework-mcp-server-command-injection https://dev.to/cverports/cve-2025-69256-serverless-command-injection-when-experimental-means-remote-shell-3g2d
Related VulnerabilitiesPoCCVE-2026-39352: Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path TraversalPoCfrappe-default-login: Frappe Framework - Default Login CredentialsPoCCVE-2025-41242: Spring Framework - Path TraversalPoCCVE-2024-38819: Spring Framework Path Traversal in Functional Web FrameworksAstro Web Framework Cloudflare /_image 服务器端请求伪造漏洞(CVE-2025-58179)Spring Framework路径遍历漏洞(CVE-2024-38819)Vmware Spring Framework 逻辑缺陷漏洞OpenOrange Business Framework访问控制错误漏洞(CVE-2024-42048)PoCCVE-2020-0646: Microsoft .NET Framework - Remote Code ExecutionPoCspring4shell-CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+PoCCVE-2016-6601: ZOHO WebNMS Framework <5.2 SP1 - Local File InclusionPoCCVE-2017-1000163: Phoenix Framework - Open Redirect