A vulnerability in the JS-YAML module for Node.js prior to version 2.0.5 allowed remote attackers to execute arbitrary code by supplying YAML input containing the !!js/function tag. The module's load function would parse this tag and use JavaScript's Function constructor to evaluate the input, effectively acting as an eval. This allowed attackers to inject and execute malicious JavaScript code in the context of the Node.js application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small proof-of-concept lab for CVE-2013-4660, demonstrating unsafe deserialization in the Node.js js-yaml library. The repo contains three files: a malicious YAML payload (PoC.yaml), a README with Docker build/run instructions, and a Dockerfile-like file named cve-2013-4660 that constructs a vulnerable containerized environment. The exploit capability is arbitrary JavaScript execution during YAML parsing through the !!js/function tag when processed by yaml.load() in js-yaml 2.0.4. The provided payload does not establish persistence or a shell; instead, it executes immediately at parse time and prints process.env, proving access to sensitive runtime data. The README reinforces this by suggesting injection of example secrets such as DB_PASSWORD and AWS_ACCESS_KEY_ID into the container before triggering the parse. Repository structure and purpose: - PoC.yaml: Contains the malicious deserialization payload. It serializes and prints environment variables, serving as the core exploit artifact. - cve-2013-4660: Builds a vulnerable Node.js lab image, installs js-yaml@2.0.4, creates app.js, reads poc.yaml from disk, and calls yaml.load(fileContents), which triggers the payload. - README.md: Documents how to build the Docker image, run the container with sample secrets, copy in PoC.yaml, and execute node app.js to observe the leak. There are no external network callbacks, hardcoded IPs, or remote C2 endpoints in the code. The attack vector is primarily file-based/local within a containerized lab: an attacker supplies a crafted YAML file that is parsed unsafely. This is a real exploit demonstration rather than a detector, but it is best classified as POC maturity because the payload is fixed and only demonstrates code execution by leaking environment variables.
This repository contains a single Metasploit module targeting a code execution vulnerability in Node.js applications that use the 'js-yaml' package (versions <2.0.5) and parse user-supplied YAML input with the load() function. The exploit abuses the unsafe !!js/function YAML tag, allowing an attacker to craft a YAML file that, when parsed, executes arbitrary JavaScript code. The module generates a malicious YAML file (default name: msf.yml) containing a self-executing JavaScript function with the attacker's payload. The exploit is weaponized, leveraging Metasploit's payload system to embed arbitrary JavaScript code. The main attack vector is through a crafted file, and the primary fingerprintable endpoint is the malicious YAML file itself. The module references CVE-2013-4660 and is suitable for use against vulnerable Node.js applications using the affected js-yaml package.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.