CVE-2019-6340 is a critical remote code execution vulnerability in Drupal Core affecting Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10, with related exposure conditions in certain Drupal 7 web services deployments. The flaw is caused by improper sanitization of data from non-form sources in some field types. When vulnerable web services functionality is enabled, an attacker can submit crafted POST or PATCH requests, and in some cases similar web-service-driven input, to inject unexpected field data that is processed unsafely by Drupal. Under affected configurations, this can result in arbitrary PHP code execution on the server. Exposure depends on the presence of enabled web services components such as Drupal 8 core RESTful Web Services or other supported service modules including JSON:API, Services, or RESTful Web Services in Drupal 7 deployments.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository contains an operational exploit chain centered on lo_upload.py plus a supporting malicious PostgreSQL shared-library payload and a Docker-based reproduction lab. The main exploit file, lo_upload.py, is a standalone Python script that sends crafted JSON POST requests to a Drupal login endpoint and abuses a SQL injection primitive to execute PostgreSQL large object functions. Its core capability is arbitrary file write to the database server filesystem: it creates a large object, uploads the local file in 8 KB chunks with lo_put, exports it to an attacker-chosen path with lo_export, then removes the large object with lo_unlink. It also includes a blind verification step using md5(pg_read_binary_file(...)) and pg_sleep timing. The included evil_shell.c is a PostgreSQL extension/shared object payload intended to be uploaded by the Python script. When PostgreSQL loads it and _PG_init executes, it writes a marker file and forks a bash reverse shell to 192.168.52.129:4444. This demonstrates the repository’s intended post-write objective: turning arbitrary file write into code execution on the database host. Repository structure: README.md is minimal; lo_upload.py is the primary exploit; evil_shell.c is the sample second-stage payload; Docker_env/docker-compose.yml provisions a local Drupal 11.3.9 + PostgreSQL 16 lab; Docker_env/setup.sh automates Drupal installation, JSON:API enablement, and seed content creation. The lab files reference SA-CORE-2026-004, while the Python exploit comments reference CVE-2019-6340-style SQLi behavior, so the repository appears to mix a reproduction environment for one Drupal issue with an exploit technique and payload chain for SQLi-to-PostgreSQL file write/RCE. Overall, this is not merely a detector or README: it is exploit code with a concrete offensive capability and a bundled RCE-oriented payload.
This repository is a small standalone Python proof-of-concept exploit for CVE-2019-6340, a Drupal RESTful Web Services remote code execution vulnerability caused by unsafe PHP deserialization. The repo contains only three files: a license, a README describing the vulnerability and usage, and a single executable script, exploit.py, which is the full exploit implementation. The exploit works by constructing a serialized PHP object gadget chain based on Guzzle/RCE1 using GuzzleHttp\Psr7\FnStream and GuzzleHttp\HandlerStack. The attacker-supplied command is embedded into the serialized object so that, upon deserialization by Drupal, the chain reaches system(command). That serialized payload is inserted into a HAL+JSON request body under link[0].options, with _links.type.href set to a Drupal REST type endpoint required for validation. Operationally, the script targets Drupal REST endpoints at /node?_format=hal_json by default using POST, specifically to avoid the page-cache limitation of older GET-based public exploits. It also supports PATCH, PUT, and GET; GET mode uses /node/{id}?_format=hal_json and is noted as cache-limited. The script handles common HTTP responses and treats HTTP 401 as likely successful exploitation because the payload is expected to deserialize before authentication failure. It also explicitly notes that request timeouts may indicate successful long-running payloads such as reverse shells. Capabilities include unauthenticated arbitrary command execution, visible command output retrieval when returned in the HTTP response, and support for blind commands or reverse shells. The code supports optional proxying, configurable timeout, verbose output, and node selection for GET mode. This is a real exploit rather than a detector, and because it accepts arbitrary operator-supplied commands but does not include a modular payload framework, its maturity is best classified as OPERATIONAL.
This repository contains a single Metasploit module: 'drupal_restws_unserialize.rb', which exploits a remote code execution (RCE) vulnerability (CVE-2019-6340) in Drupal's RESTful Web Services module. The exploit targets Drupal versions prior to 8.5.11 and 8.6.10, where a crafted HTTP request to the /node REST endpoint can trigger a PHP unserialize vulnerability, allowing arbitrary code execution. The module supports both PHP and Unix command payloads, enabling attackers to execute arbitrary PHP code or system commands (such as opening a reverse shell or running 'id'). The exploit is weaponized, allowing easy payload customization via Metasploit. The main endpoints involved are '/node' (for the REST API) and '/rest/type/shortcut/default' (used in the payload). The module is designed for remote, unauthenticated exploitation over the network, provided the target is misconfigured and vulnerable. The code is written in Ruby and is structured as a standard Metasploit exploit module, with options for HTTP method, node ID, and output dumping.
This repository is a comprehensive exploit library (exphub) containing operational exploit scripts for a wide range of high-profile vulnerabilities affecting popular enterprise software. The structure is organized by product (e.g., drupal/, f5/, fastjson/, jboss/, nexus/, ofbiz/, shiro/, solr/, spring/, struts2/, tomcat/, weblogic/), with each directory containing Python or Java scripts for specific CVEs. The scripts are primarily remote code execution (RCE) exploits, but also include file read, webshell upload, SSRF, and administrative bypasses. Many scripts provide interactive shells or allow arbitrary command execution, and some require authentication. The repository includes both proof-of-concept (POC) and full exploit scripts, with detailed usage instructions embedded in the code and readme files. The attack vector is predominantly network-based, targeting HTTP(S) endpoints, and the scripts are suitable for both vulnerability validation and exploitation. The codebase is mature, with operational exploits for each vulnerability, and is a valuable resource for penetration testers and red teamers.
This repository contains a proof-of-concept (POC) exploit for CVE-2019-6340, a remote code execution vulnerability in Drupal (tested on version 8.6.9). The repository consists of a README.md file with usage instructions and a single Python script (poc.py) that performs the exploit. The script takes four arguments: the target Drupal URL, a PHP function name, a command to execute, and a node number. It crafts a malicious JSON payload that abuses PHP object deserialization in the GuzzleHttp library to execute arbitrary PHP functions and commands on the target server. The exploit is network-based and requires the attacker to know a valid node number on the target Drupal instance. The main endpoint targeted is the Drupal node REST API with the '_format=hal_json' parameter. The exploit demonstrates remote code execution capabilities but does not include post-exploitation features or advanced payload customization, making it a POC-level exploit.
This repository contains a Python exploit script (CVE-2019-6340.py) and a README for CVE-2019-6340, a critical remote code execution vulnerability in Drupal 8's REST API (SA-CORE-2019-003). The exploit targets Drupal 8 installations with the REST module enabled and misconfigured, allowing unauthenticated attackers to send specially crafted POST requests to the /node/ endpoint with hal_json format. The script constructs a malicious JSON payload that abuses PHP object deserialization to execute arbitrary system commands on the server as the web server user. The README provides detailed usage instructions, including Docker setup for testing, example commands, and sample requests/responses. The main entry point is CVE-2019-6340.py, which takes a target URL and a command to execute. The exploit is operational, providing direct RCE if the target is vulnerable. Notable endpoints include /node/?_format=hal_json and the use of http://localhost/rest/type/shortcut/default in the payload. The repository is focused and practical for testing or exploiting this specific Drupal vulnerability.
This repository provides a proof-of-concept exploit environment for CVE-2019-6340, a remote code execution vulnerability in Drupal 8's REST module. The repository includes a Dockerfile that builds a vulnerable Drupal 8.6.9 instance with the REST and HAL modules enabled and pre-configured. The 'create_node.php' script is used to create a test node in the Drupal instance. The README.md details how to run the vulnerable environment and demonstrates the exploit using crafted HTTP requests (GET and POST) with a malicious serialized PHP object in the JSON payload. This object leverages PHP object injection to execute arbitrary system commands on the server. The exploit targets the REST API endpoints exposed by the Drupal instance, specifically '/node/1?_format=hal_json' and '/node/?_format=hal_json'. The repository is intended for educational and testing purposes, providing a self-contained environment to reproduce and study the vulnerability.
This repository provides a working proof-of-concept exploit for CVE-2019-6340, a critical remote code execution vulnerability in Drupal 8.x (<= 8.6.9) when the RESTful Web Services module is enabled. The main exploit script, 'cve-2019-6340.py', is a Python tool that automates the exploitation process: it discovers a usable node, checks for vulnerability, and sends a specially crafted HTTP request to the Drupal REST API endpoint. The exploit leverages PHP object injection by sending a serialized GuzzleHttp\Psr7\FnStream object in the 'link.options' property, which, when deserialized by the vulnerable Drupal instance, results in arbitrary command execution via the 'system' function. The repository also includes 'exploit.txt' and 'payloads.txt', which provide technical background and example payloads, respectively. The exploit is unauthenticated and operates over the network, targeting the REST API endpoints of Drupal installations. The exploit's effectiveness depends on the target's cache state, as noted in the documentation. No detection scripts or fake code are present; this is a functional exploit with operational maturity.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A highly critical remote code execution vulnerability in Drupal Core related to Drupal 8 RESTful Web Services (and certain modules) that can allow arbitrary PHP code execution via crafted PUT/PATCH/POST requests.
Specific vulnerability listed as an example in EPSS probability rankings; the content does not describe the flaw itself.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.