CVE-2026-101080 Tencent AI-Infra-Guard 路径遍历漏洞
影响本地攻击者可越权读取任意文件
Tencent AI-Infra-Guard 的 skill_scan/tools/dir/dir_actions.py 中 startsWith 函数存在路径遍历漏洞。攻击者可在本地构造恶意路径绕过目录限制,访问预期目录之外的文件。该漏洞利用代码已公开,存在被实际利用的可能。
影响范围
Tencent AI-Infra-Guard 4.5.2 及 4.6.2 等受影响版本;官方称升级到 4.6.0 可缓解(版本号关系以官方公告为准)。
漏洞详情
漏洞类型为路径遍历(Path Traversal)。成因是 startsWith 对路径前缀的校验不严谨,未正确规范化路径,导致可通过 ../ 等构造绕过目录限制。攻击者需在本地运行环境触发该文件访问逻辑,从而读取越权文件。
利用条件与风险
利用前提是攻击者已能在本地访问或调用该组件功能,属于本地攻击,CVSS 4.8 为中危。由于 PoC 已公开,具备本地访问条件的场景下实战风险上升。
修复建议
官方建议升级到 4.6.0 或更高版本,补丁标识为 ac0384edc9dbea3b226edefcf50613bd8509134f。临时缓解可限制本地不可信用户对该组件的调用权限,并对传入路径做规范化与白名单校验。
A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skill_scan/tools/dir/dir_actions.py of the component File Access. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version 4.6.0 is able to mitigate this issue. The identifier of the patch is ac0384edc9dbea3b226edefcf50613bd8509134f. You should upgrade the affected component.