Meshery /api/system/fileDownload 文件读取漏洞

2026-04-10 Meshery PoC No

Description

Meshery 平台 /api/system/fileDownload 接口存在未授权任意文件读取漏洞,该接口未对传入的 file 参数做路径安全校验与权限控制,攻击者可构造 ../ 目录穿越字符,直接读取服务器上 /etc/passwd 等任意系统敏感文件,导致配置信息、密钥、用户凭证等核心数据泄露。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References

Related Vulnerabilities