天下漏洞,尽知其名
CRITICAL 重点关注

CVE-2026-102911 zosmaai pi-llm-wiki 操作系统命令注入漏洞

影响攻击者可远程执行任意操作系统命令

AI 研判

zosmaai pi-llm-wiki 0.11.7 及以下版本中,wiki_capture_source MCP 工具的实现文件 mcp/index.ts 存在操作系统命令注入漏洞。攻击者可通过操纵 url 参数注入并执行任意系统命令,且该攻击可远程发起。目前漏洞利用代码已公开,存在被实际利用的风险。

影响范围

zosmaai pi-llm-wiki

zosmaai pi-llm-wiki 0.11.7 及更早版本;0.11.8 版本已修复该问题。

漏洞详情

该漏洞属于操作系统命令注入(OS Command Injection)。成因是 wiki_capture_source MCP 工具在处理 url 参数时未进行充分的过滤或转义,直接将其拼接到系统命令中执行。攻击者只需构造恶意的 url 参数值,即可在目标主机上以应用进程权限执行任意命令。由于利用代码已公开,攻击门槛较低。

利用条件与风险

利用前提是目标暴露并启用了 wiki_capture_source MCP 工具且可被远程访问。CVSS 评分高达 9.9,且已有公开 EXP,实战中被主动利用的风险很高。

修复建议

官方建议升级至 0.11.8 版本(补丁提交 360867034e79175b45c8e04a98e4ca712bbaca35)。临时缓解措施包括禁用或限制 wiki_capture_source MCP 工具的远程访问,并对 url 参数进行严格校验与过滤。

原始情报

A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is called 360867034e79175b45c8e04a98e4ca712bbaca35. Upgrading the affected component is advised.