Gerapy, a distributed crawler management framework, prior to version 0.9.8, contains a vulnerability that allows remote code execution. The vulnerability enables an attacker to execute arbitrary code on the server running a vulnerable version of Gerapy.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Python exploit script (50640.py) and a short README with usage steps. The exploit targets Gerapy versions prior to 0.9.8 (CVE-2021-43857) and achieves authenticated remote code execution. Core flow in 50640.py: 1) Builds base URL http://<target_ip>:<target_port> and creates a requests.Session. 2) Authenticates to /api/user/auth using hardcoded credentials (admin/admin by default) to obtain a token. 3) Uses the token in an Authorization: Token <token> header. 4) Queries /api/project/index to obtain the first project name, then calls /api/project/<name>/build to retrieve the project id. 5) Spawns a local netcat listener (nc -nvlp <localport>). 6) Sends a POST to /api/project/<id>/parse with a JSON-like body containing a backtick-wrapped bash reverse shell command in the spider field. This is intended to be evaluated server-side, resulting in a reverse shell to <LHOST>:<LPORT>. Notable characteristics: - Network-based, authenticated exploit; not a scanner/detector. - Payload is a basic hardcoded bash reverse shell using /dev/tcp; customization is via CLI args for LHOST/LPORT. - Assumes at least one project exists (uses the first project returned).
This repository contains a Python proof-of-concept exploit for CVE-2021-43857, a remote code execution vulnerability in Gerapy versions prior to 0.9.8. The exploit automates the process of authenticating to the Gerapy API (using default credentials), creating a project if necessary, and delivering a reverse shell payload via a vulnerable API endpoint. The payload is a bash reverse shell that connects back to the attacker's machine, where a netcat listener is automatically started by the script. The repository consists of three files: a LICENSE, a README.md with usage instructions and context, and the main exploit script (exploit.py). The exploit targets the Gerapy web application's API endpoints over HTTP, and requires the attacker to have network access to the target and the ability to authenticate (default credentials are assumed). The exploit is a functional proof-of-concept and does not belong to any exploit framework.
This repository contains a single Python exploit script (exploit.py) targeting CVE-2021-43857 in Gerapy versions prior to 0.9.8. The exploit automates the process of authenticating to a vulnerable Gerapy instance, retrieving the first available project, and exploiting a command injection vulnerability to execute a reverse shell payload. The script requires the attacker to provide the target's address, port, credentials (default admin/admin), and the attacker's own host and port for the reverse shell listener. The payload is a bash reverse shell, and the script also launches a netcat listener to catch the shell. The main attack vector is network-based, exploiting Gerapy's HTTP API endpoints. The repository is well-structured, with clear separation of logic for authentication, project enumeration, and payload delivery. No detection or fake code is present; this is a functional exploit script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.