mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-05-29 06:31:32 +00:00
show_snapshot.py unpickled a user-supplied path unconditionally. pickle.loads is equivalent to arbitrary code execution, so a snapshot from an untrusted source = RCE. Require an explicit --i-trust-this-file acknowledgement before calling pickle.loads, and emit a stderr warning when proceeding. Co-authored-by: Jiahui-Gu <jiahuigu@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| bioinformatics | ||
| darwinian-evolver | ||
| domain-intel | ||
| drug-discovery | ||
| duckduckgo-search | ||
| gitnexus-explorer | ||
| osint-investigation | ||
| parallel-cli | ||
| qmd | ||
| scrapling | ||
| searxng-search | ||