CVE-2018-21268 is a command injection vulnerability in the traceroute (node-traceroute) package for Node.js, affecting versions through 1.0.0. The vulnerability arises from improper sanitization of the 'host' parameter, which is passed directly to the Child.exec() method. This allows an attacker to inject arbitrary OS commands by including special characters (such as a newline) in the host parameter.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small synthetic vulnerable Node.js demo application intended to showcase exploitable dependency findings rather than serve as a production exploit toolkit. It contains 6 files total, with the primary logic in src/main.js, package metadata in package.json/package-lock.json, a Dockerfile for containerized execution, and a README explaining the intentionally vulnerable design. The main capability is a remotely reachable command-injection path through the Express GET endpoint /traceroute. That handler passes req.query.host directly into traceroute.trace() without validation, matching the README’s description of CVE-2018-21268 in traceroute@1.0.0. This creates a web-to-command-execution attack path where attacker-controlled HTTP input can reach an OS command context through the vulnerable library. A second route, POST /render, uses pdf-image@2.0.0 and references CVE-2018-3757, but the code applies a strict regex (SAFE_PATH_RE) to req.body.path before constructing PDFImage. Based on the implementation and README, this path is intentionally included as a non-exploitable contrast case. Repository structure is straightforward: src/main.js starts an Express JSON API and listens on port 3000; Dockerfile builds a minimal node:18-alpine container and exposes port 3000; package files pin express 4.18.2, traceroute 1.0.0, and pdf-image 2.0.0. Overall, this is an operational demo of a vulnerable web service whose primary exploit capability is remote command injection via the /traceroute endpoint.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.