CVE-2021-41163 affects Discourse, the open source community discussion platform. In affected versions, maliciously crafted requests can trigger remote code execution due to insufficient validation of subscribe_url values. The vulnerable condition is associated with request handling on the /webhooks/aws path, where untrusted input was not properly validated before being used in a security-sensitive context. The issue has been patched in the latest stable, beta, and tests-passed releases of Discourse.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Ruby exploit script (CVE-2021-41163.rb) targeting a critical remote code execution (RCE) vulnerability in Discourse (CVE-2021-41163). The exploit abuses the theme import functionality in Discourse versions prior to 2.7.8 and 2.8.0.beta6, allowing attackers to execute arbitrary code on the server. The script automates the exploitation process: it retrieves a CSRF token and session cookies, checks for admin access (and attempts several admin bypass techniques), and then tests multiple RCE vectors by uploading malicious theme ZIP files containing JavaScript, CSS, Handlebars templates, or YAML settings designed to trigger code execution. The exploit is operational and provides evidence of successful RCE if the target is vulnerable. The repository is structured with a single main exploit file, a license, a minimal README, and a .gitignore. The main entry point is CVE-2021-41163.rb, which is a standalone Ruby script requiring the target Discourse URL as input.
This repository contains a Ruby exploit script (CVE-2021-41163.rb) targeting Discourse forum software versions prior to 2.7.8 and 2.8.0.beta6. The exploit leverages a remote code execution vulnerability in the theme import functionality, allowing an authenticated attacker to upload a malicious theme archive. The payload, embedded as JavaScript within the theme, attempts to execute system commands (such as 'id'), read sensitive files (like '/etc/passwd'), and exfiltrate the results to an external server (http://evil.com). It also includes browser-based actions to steal cookies and CSRF tokens if executed in a browser context. The script automates the process of creating the malicious theme, uploading it, and verifying exploitation. The repository is structured with a single main exploit script, a license, a minimal README, and a .gitignore. The exploit is operational and provides real RCE capabilities if used against a vulnerable, authenticated Discourse instance.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.