Donut AI Security Disclosure Evidence

CVE 申请记录CVE Filing Records

Donut Browser 阶段 9 个 CVE 申请记录集中放在本页。正式发布版本将以实际获得的 CVE 编号替换 Ticket ID,并补充最终 CWE / CVSS。

This page collects the 9 CVE filing records from the Donut Browser phase. The official release will replace the Ticket IDs with the actual CVE numbers and add final CWE / CVSS details.

申请概况Filing Overview

申请要点Filing highlights
  • 申请提交日期:2026 年 3 月 21 日Submission date: 2026-03-21
  • 申请数量:9 个 CVE 候选编号Count: 9 candidate CVE IDs
  • 申请发起方:Lucifiel(独立安全研究员)Filed by: Lucifiel (independent security researcher)
  • 申请受理平台:MITRE / 相应 CNAReceiving platform: MITRE / the relevant CNA
  • 状态:截至公开披露仍在 CNA / 受理平台流程中;正式 CVE 编号下发后,将在本页补充最终 CVSS 与 CWE 映射。Status: as of public disclosure, still in the CNA / receiving-platform process; once official CVE numbers are issued, the final CVSS and CWE mapping will be added here.

漏洞条目对应关系Vulnerability Mapping

下表为草案阶段映射,最终公开版本将以正式获得的 CVE 编号替换 Ticket ID 并补充 CWE / CVSS 信息:

The table below is a draft-stage mapping; the final public version will replace Ticket IDs with the official CVE numbers and add CWE / CVSS information:

Ticket IDTicket ID对应漏洞Mapped vuln漏洞标题Vulnerability titleCWE 候选CWE candidate严重性Severity
2012016DB-1服务端交易自动签名 / 执行链路缺失强授权边界Server-side transaction auto-signing / execution path lacks a strong authorization boundaryCWE-862 / CWE-306Critical
2012018DB-4CORS 子域通配符与 credentials 组合CORS subdomain-wildcard combined with credentialsCWE-942Critical
2012020DB-3钱包 / 资产接口 IDORWallet / asset API IDORCWE-639Critical
2012022DB-6Role 参数注入Role-parameter injectionCWE-20 / CWE-915High
2012024DB-5MCP 工具层认证或权限边界不足Insufficient auth or privilege boundary in the MCP tool layerCWE-287 / CWE-285Critical
2012026DB-7弱认证 / 无认证钱包创建Weak / no-auth wallet creationCWE-306High
2012030DB-8Credits / 使用次数限制绕过Credits / usage-limit bypassCWE-840High
2012032DB-9AI Agent 配置与 Prompt 泄露AI Agent config and prompt leakageCWE-200 / CWE-552High
2012034DB-10跨用户限价单取消Cross-user limit-order cancellationCWE-639High

说明Notes:

  1. Ticket ID 为申请阶段编号,正式发布版本会替换为实际 CVE 编号。Ticket IDs are filing-stage numbers; the final version will replace them with actual CVE numbers.
  2. CWE 候选为研究员推荐项,最终以受理平台审定结果为准。CWE candidates are the researcher’s suggestions; the receiving platform’s determination is authoritative.
  3. CVSS 数值与向量将在正式 CVE 编号下发后补充。CVSS scores and vectors will be added once official CVE numbers are issued.

与 49 漏洞总览的关系Relationship to the 49-Vuln Overview

完整 49 漏洞清单见 主披露 §漏洞总览

For the full 49-vulnerability list, see the main disclosure §Vulnerability Overview.