CVE-2026-102874 HKUDS AnyTool 操作系统命令注入漏洞
影响攻击者可远程执行任意系统命令
HKUDS AnyTool 0.1.0 的本地服务端组件 Execute Endpoint 存在操作系统命令注入漏洞。问题出在 anytool/local_server/main.py 中的 subprocess.run 函数,对 command/shell 参数处理不当。该漏洞可被远程利用,且利用代码已公开。
影响范围
受影响版本为 HKUDS AnyTool 0.1.0,其他版本是否受影响暂无公开信息。
漏洞详情
漏洞类型为操作系统命令注入(OS Command Injection)。成因是 Execute Endpoint 在调用 subprocess.run 时未对用户可控的 command/shell 参数做充分过滤或转义,导致攻击者可将恶意命令拼接进系统调用中执行。攻击者可远程发送特制请求触发该接口,从而在目标主机上执行任意命令。
利用条件与风险
利用前提是目标 AnyTool 本地服务端接口可被远程访问,且无需额外认证(或认证可绕过)。由于利用代码已公开,实战中被扫描和攻击的风险较高。
修复建议
官方尚未发布修复版本或回应,建议关注项目更新。临时缓解措施包括:限制该服务端接口的网络访问、增加认证与输入校验、避免将用户输入直接传入 subprocess.run,或使用参数列表方式调用并禁用 shell=True。
A vulnerability was identified in HKUDS AnyTool 0.1.0. Affected is the function subprocess.run of the file anytool/local_server/main.py of the component Execute Endpoint. The manipulation of the argument command/shell leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.