CVE-2021-22204 is an eval-injection vulnerability in ExifTool versions 7.44 and later when parsing DjVu files. Improper neutralization of user-controlled DjVu data permits attacker-controlled content to reach dynamically evaluated code, enabling arbitrary code execution during parsing of a malicious image.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
10 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone exploit PoC for GitLab unauthenticated RCE via CVE-2021-22205. It contains two files: a README describing the vulnerability and impact, and a single Python exploit script. The script is the operational component. It generates a malicious DjVu-based payload by combining two hardcoded binary blobs with an injected command string. That command is a base64-wrapped bash reverse shell that connects back to an attacker-supplied LHOST and LPORT. The exploit then starts a local TCP listener, uploads the crafted file to the target over HTTP POST using the requests library, and waits for an inbound shell connection. If the callback arrives, it provides an interactive shell over the socket using select() to multiplex stdin and the remote connection. Structurally, exploit.py has four main functions: generate_malicious_djvu() builds the malicious file; upload_exploit() sends it to the target URL with a random 8-character path suffix; listener_thread() binds and waits up to 60 seconds for the reverse shell; and interactive_shell() provides operator interaction with the compromised host. The main() function parses arguments, launches the listener and uploader in separate threads, and transitions into shell handling on success. The exploit’s primary capability is unauthenticated remote code execution against vulnerable GitLab CE/EE instances, resulting in an interactive reverse shell. It is not a scanner or detection script. It is best classified as OPERATIONAL rather than WEAPONIZED because it includes a working hardcoded reverse-shell payload but lacks broader framework integration, target validation, or payload modularity. Notably, the upload path in the code is a generic random URL suffix rather than a clearly GitLab-specific known endpoint, which may indicate the PoC is simplified or assumes a particular routing condition; however, the intended purpose is clearly exploitation of CVE-2021-22205 through malicious file upload and ExifTool processing.
This repository is a small standalone exploit for CVE-2021-22204 in ExifTool. It contains one executable Python script, a README, and a license. The Python script is the sole entry point and automates creation of a malicious DjVu-based image that abuses ExifTool's vulnerable DjVu metadata parsing to achieve arbitrary code execution. Structurally, exploit.py accepts either reverse-shell mode (-s IP PORT) or single-command mode (-c "command"). It builds a Perl payload, base64-encodes it, and embeds it into a DjVu metadata string using the \c construct that triggers code evaluation in the vulnerable parsing path. The script then writes the payload to a temporary file, compresses it with bzz, packages it into a DjVu file with djvumake, and finally renames/copies the result to image.jpg for easier delivery to targets that will process uploaded images. Main exploit capability: arbitrary code execution on any system that runs vulnerable ExifTool against the generated file. In reverse-shell mode, the payload uses Perl's Socket module to connect back to an attacker-controlled IP and port and then redirects STDIN/STDOUT/STDERR to spawn /bin/sh -i. In command mode, it executes a single attacker-provided command via Perl system(). This is a real exploit rather than a detector. It does not directly contact a hardcoded remote endpoint itself; instead, it generates a malicious file whose embedded payload may later initiate a TCP callback to an attacker-specified host. The exploit is operational but simple: payloads are customizable through command-line arguments, yet the repository is not part of a larger exploitation framework.
This repository is a small standalone exploit for CVE-2021-22204 in ExifTool. It contains one Python script (`exploit.py`), a README, and a license. The script is the sole entry point and automates creation of a malicious DjVu-based file that is renamed to `image.jpg` for delivery to a target environment where ExifTool will parse it. The exploit works by building a Perl payload, base64-encoding it, and embedding it into DjVu metadata using the `\c` ExifTool evaluation primitive described in the vulnerability. Two modes are supported: a custom command mode (`-c`) that wraps the supplied command in Perl `system(...)`, and a reverse shell mode (`-s IP PORT`) that uses Perl Socket functions to connect back to an attacker-controlled TCP listener and execute `/bin/sh -i` with stdin/stdout/stderr redirected over the socket. Operationally, the script writes a temporary `payload` file, compresses it with `bzz` into `payload.bzz`, then invokes `djvumake` to create `exploit.djvu`, and finally copies that file to `image.jpg`. It cleans up intermediate artifacts afterward. The exploit does not directly contact a victim over the network itself; instead, it produces a malicious file for later delivery. The only network-relevant endpoint is the operator-supplied reverse-shell callback address embedded in the payload. Repository structure is minimal and purpose-built: `README.md` documents affected versions, prerequisites, and usage; `exploit.py` implements payload generation and file construction; `LICENSE` is standard MIT text. This is a real exploit, not a detector, and its maturity is best classified as OPERATIONAL because it includes a working payload generator with basic customization but is not part of a larger exploitation framework.
This repository is an exploit for CVE-2021-22204, a critical command injection vulnerability in ExifTool (prior to version 12.24) when processing DjVu files embedded in image metadata. The repository contains five files: a Dockerfile for setting up the environment, a docker-compose.yml for container orchestration, a configfile for custom EXIF tags, a README.md with usage instructions, and the main exploit script exploit.py. The exploit.py script generates a malicious DjVu file containing a base64-encoded Perl reverse shell payload, compresses it, and embeds it as a custom EXIF tag in a JPEG image (image.jpg) using ExifTool. When a vulnerable ExifTool instance processes this image, it executes the payload, resulting in a reverse shell to the attacker's specified IP and port. The repository is operational and provides a working exploit chain, but the payload is hardcoded and requires manual configuration of the attacker's IP and port.
This repository contains a single Metasploit module targeting CVE-2021-22204, a Perl injection vulnerability in ExifTool's DjVu ANT parsing code (versions 7.44 through 12.23). The module generates a malicious DjVu, JPEG, or TIFF file with a crafted ANT chunk that injects a shell command via Perl backticks. When a vulnerable ExifTool instance processes the file, the injected command is executed on the target system. The module leverages Metasploit's payload system to allow arbitrary command execution, making it a weaponized exploit. The code references template files (msf.jpg, msf.tif, msf.djvu) for constructing the malicious files, and the main entry point is the Ruby file provided. No network endpoints are present; the attack vector is file-based. The repository is structured as a typical Metasploit exploit module and is intended for use within the Metasploit Framework.
This repository contains a single Metasploit module (gitlab_exif_rce.rb) that exploits an unauthenticated remote command injection vulnerability in GitLab CE and EE (CVE-2021-22205, leveraging CVE-2021-22204 in ExifTool). The exploit works by uploading a specially crafted JPEG file to a vulnerable GitLab instance, triggering ExifTool to execute arbitrary commands as the 'git' user. The module supports both direct command execution and staged payloads (such as reverse shells or Meterpreter sessions), and is weaponized for operational use. The module includes logic to check if the target is a GitLab instance and whether it is vulnerable, and it provides options for different payload types. The only file in the repository is written in Ruby and is structured as a standard Metasploit exploit module, making use of the framework's HTTP client and command stager utilities. The main attack vector is network-based, targeting the GitLab web interface via HTTP POST requests to arbitrary URIs. No hardcoded IPs or domains are present; the module is designed to be used against user-specified targets.
This repository provides a working exploit for CVE-2021-22204, a critical vulnerability in ExifTool (prior to version 12.24) that allows remote code execution via crafted image files. The main exploit is implemented in 'exploit.py', which generates a malicious DjVu file containing a base64-encoded Perl reverse shell payload. This payload is embedded as EXIF metadata into a JPEG image ('image.jpg') using ExifTool with a custom configuration ('configfile'). When a vulnerable ExifTool instance processes this image, the payload is executed, resulting in a reverse shell to the attacker's specified IP and port. The repository also includes a 'lab' directory with a Dockerized Perl web application that simulates a backend service processing user-supplied images with ExifTool, providing a practical environment for testing the exploit. The exploit requires the attacker to specify their IP and port in 'exploit.py' and to have the necessary tools (djvulibre, exiftool) installed. The attack vector is both local (when a user processes a malicious image) and network-based (when a web service processes user-supplied images).
This repository provides a Bash script (CVE-2021-22204.sh) that automates the creation of a malicious JPEG image exploiting CVE-2021-22204, a remote code execution vulnerability in ExifTool (versions 7.44 and up). The script generates a DjVu annotation chunk containing a user-supplied Perl payload, which can be either an arbitrary system command or a reverse shell. The payload is embedded into a JPEG file using ExifTool with a custom configuration. When a vulnerable ExifTool instance processes the crafted image, the embedded Perl code is executed, leading to arbitrary code execution on the target. The repository includes a README with detailed usage instructions and background on the vulnerability. The main attack vector is via a malicious file, and the exploit is operational, providing real payloads for both command execution and reverse shell scenarios.
This repository provides a working exploit for CVE-2021-22204, a critical arbitrary code execution vulnerability in ExifTool versions 7.44 through 12.23. The main exploit script, 'exploit-CVE-2021-22204.py', is a Python program that generates a malicious JPEG image containing a specially crafted DjVu payload. The payload is designed to execute arbitrary commands or open a reverse shell when the image is processed by a vulnerable ExifTool instance. The exploit supports both custom command execution and reverse shell payloads, with options to use a custom image or generate a minimal JPEG. The repository includes a Dockerfile for setting up a vulnerable environment and a README with detailed usage instructions. The attack vector is local, requiring the attacker to supply a malicious image to a system that processes files with ExifTool. The exploit is operational and can be used for both proof-of-concept and practical exploitation in authorized testing scenarios. No network endpoints are hardcoded, but the reverse shell mode requires the attacker to specify their own IP and port.
This repository provides a proof-of-concept exploit for CVE-2021-22204, a vulnerability in ExifTool (versions 7.44 to 12.23) that allows arbitrary code execution via crafted DjVu image files. The main script, 'craft_a_djvu_exploit.sh', is a Bash script that generates a malicious image file ('delicate.jpg') containing a user-supplied shell command. The exploit works by embedding the command into the DjVu file structure in a way that triggers code execution when the file is processed by a vulnerable version of exiftool. The repository includes a README with usage instructions and references. No network endpoints are present; the attack vector is local, requiring the victim to process the crafted file. The exploit is a POC and does not include advanced payloads or automation for delivery.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prior ExifTool argument injection vulnerability mentioned as background and comparison for the Gotenberg issues.
Ранее известная уязвимость ExifTool, связанная с недостаточной очисткой пользовательского ввода перед передачей в eval, упомянута как отправная точка для поиска аналогичных проблем.
A prior ExifTool vulnerability referenced for comparison, involving weak regex-based sanitization that allowed user input to reach an eval sink.
A vulnerability in ExifTool referenced as a path to root access / privilege escalation in the attack chain.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.