安全性: helpers::tokenizeCommand 中的命令允许列表通过双引号中的命令替换进行绕过
作者: Pcmhacker-piro创建于 2026年9月11日更新于 2026年9月11日
Describe the bug
A security flaw in helpers::tokenizeCommand (helpers.cpp) allows arbitrary command execution that bypasses commandAllowList when double quotes are used.
内容来源: neutralinojs/neutralinojs