CVE-2022-25845 is a deserialization of untrusted data vulnerability in Alibaba Fastjson versions before 1.2.83. Under certain conditions, an attacker can bypass Fastjson's default AutoType shutdown restrictions, allowing attacker-controlled type information to reach unsafe deserialization behavior and enabling attacks against remote servers.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a multi-part Fastjson research and exploitation lab centered on remote class loading via attacker-controlled @type values. It contains: (1) a top-level command-capable exploit for Fastjson 1.2.83 on JDK 8, (2) a modern-fd marker-only reproduction for Fastjson 1.2.83 on Linux/JDK 17 using a retained remote-JAR file-descriptor chain, (3) a fastjson2 marker-only lab showing remote class fetch/initialization through polymorphic parsing paths, and (4) Python scanner tooling for passive detection, static artifact triage, and safe active reachability probing. The main exploit path is the top-level lab. attacker/Gen.java uses ASM to generate a malicious class whose internal name is a crafted URL-shaped binary name such as jar:http://attacker:8000/probe!/POC and which is annotated with com.alibaba.fastjson.annotation.JSONType. Its static initializer is the payload: it prints a banner, creates /tmp/PWNED, and executes an arbitrary shell command through Runtime.getRuntime().exec(["/bin/sh","-c",cmd]). attacker/AttackerServer.java serves the generated JAR from /www/probe over HTTP on port 8000. target/src/VulnApp.java creates a Spring Boot LaunchedURLClassLoader, sets it as Fastjson's default classloader, and exposes /parse on port 8080; it parses attacker-controlled JSON with JSON.parseObject(body, Dto.class) while AutoType remains disabled. exploit/exploit.sh sends the crafted payload to http://127.0.0.1:8080/parse and then checks /tmp/PWNED inside the target container as proof of code execution. The modern-fd/ subtree is a more constrained, marker-only reproduction of the Linux/JDK 17 continuation. It uses a Spring Boot 3.2.0 target with a fixed DTO containing List<Object> and the exact sink JSON.parseObject(body, BoundEnvelope.class). The artifact builder generates an inert seed class plus many fdN/Exception classes whose internal names are jar:file:/proc/self/fd/N!/fdN/Exception and whose static initializers only set FASTJSON_MODERN_FD_MARKER. Scripts automate positive and control cases and collect evidence. The fastjson2/ subtree is another marker-only lab. It demonstrates that fastjson2 default behavior can still reach ClassLoader.loadClass() when parsing polymorphic types via @JSONType(seeAlso) or Jackson @JsonSubTypes. The artifact server hosts marker-only JARs at /probe and /probeJ; the target exposes /parse with multiple modes, /marker, /debug, and /info. On JDK 8 the remote class can be defined and initialized; on JDK 17 the repository documents SSRF/fetch behavior with class-format failure. The scanner/ subtree is defensive tooling, not exploitation: fjdetect.py passively detects suspicious remote-JAR and FD-chain payloads in JSON/logs; fjscan_static.py inventories archives for vulnerable Fastjson/Spring Boot compositions; fjscan_probe.py and fjpayload.py generate safe reachability probes and canary payloads. Overall, the repository is a real exploit/research repo with both offensive proof-of-concept code and defensive detection utilities.
This repository is a proof-of-concept (POC) exploit for CVE-2022-25845, a remote code execution vulnerability in Alibaba Fastjson 1.2.62 when autoType is enabled. The repository contains Java source code and a Maven build file. The main exploit logic is in 'src/main/java/Main.java', which crafts a malicious JSON payload that leverages Fastjson's autoType feature to trigger a JNDI lookup to 'ldap://localhost:1389/Evil'. The 'Evil.java' class, when loaded, executes the 'calc' command, demonstrating arbitrary code execution. The exploit requires the target application to deserialize untrusted JSON with autoType enabled and to have the vulnerable Fastjson version in use. The repository does not include a full attack chain (e.g., LDAP server setup), but demonstrates the core vulnerability and payload execution.
This repository provides a working exploit for CVE-2022-25845, a deserialization vulnerability in Alibaba Fastjson 1.2.80, demonstrated in a Spring Boot environment. The main exploit script (exp.py) is written in Python and automates a multi-step attack: 1. It interacts with a vulnerable /json HTTP endpoint that deserializes user-supplied JSON using Fastjson. 2. The exploit first manipulates Fastjson's internal cache, then reads the Tomcat docbase path from the server, and finally writes a malicious Java class (PocException.class) to the server's file system in the appropriate location. 3. The payload (PocException.class) is a Java class that, when loaded, executes an OS command ('touch /tmp/pwned') as a demonstration of code execution. 4. The exploit then triggers the loading of this class, resulting in arbitrary code execution on the server. The repository includes: - exp.py: The main exploit script. - payload/: Contains the Java source and compiled class for the payload, as well as JSON payloads for each step of the attack. - demo/: A sample vulnerable Spring Boot application configured to use Fastjson 1.2.80 and expose the /json endpoint. The exploit is operational and demonstrates real code execution, but the payload is hardcoded. The attack vector is network-based, targeting HTTP endpoints that use Fastjson for deserialization. The repository is well-structured for both demonstration and practical exploitation of the vulnerability.
This repository is a proof-of-concept exploit for CVE-2022-25845, targeting Java applications using fastjson (1.2.80) and commons-io (2.7) within a Spring Boot (2.6.6) environment. The exploit demonstrates a multi-step attack chain: 1. It abuses fastjson's autotype feature to introduce dangerous classes into the deserialization cache. 2. It reads sensitive file paths from the server (such as Tomcat's docbase) using crafted JSON payloads and the file:// protocol. 3. It writes a malicious Java class (com.chenzai.HackException) to the server's file system, which is designed to execute arbitrary system commands. 4. It triggers the loading of this class, resulting in command execution (e.g., creating /tmp/pwned). The main exploit logic is in src/test/java/POC.java, which automates the attack steps by sending crafted JSON payloads (stored in the payloads/ directory) to the vulnerable /json endpoint. The repository includes a Dockerfile for easy deployment of the vulnerable application, and the README provides detailed exploitation steps. The attack vector is network-based, requiring access to the vulnerable HTTP endpoint. The exploit is operational, providing a working payload for arbitrary command execution on the target server.
This repository is a proof-of-concept (POC) for exploiting deserialization vulnerabilities in Alibaba Fastjson version 1.2.80. The project is structured as a Maven Java project and includes three main Java files: - Evil.java: Defines a Groovy AST transformation that executes a system command (launches gnome-calculator) when loaded, serving as a payload for code execution. - aspectj.java: Contains JSON payloads that exploit Fastjson deserialization to trigger gadget chains in AspectJ, including a payload that attempts to read the /etc/passwd file. - groovy.java: Contains JSON payloads that exploit Fastjson deserialization to trigger gadget chains in Groovy, including a payload that manipulates the classpath to load classes from a remote URL (http://classload.hack.com/). The exploit demonstrates both arbitrary code execution and file read capabilities by leveraging known gadget chains in Groovy and AspectJ when Fastjson processes attacker-controlled JSON. The attack vector is network-based, as the exploit assumes the target application receives JSON input from an external source. The endpoints identified include a file path (/etc/passwd) and a remote URL (http://classload.hack.com/), both used in the demonstration payloads. The repository is a clear POC and does not include weaponized or framework-level automation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An earlier FastJson AutoType bypass vulnerability mentioned for comparison with CVE-2026-16723.
Fastjson autoType shutdown-restriction bypass leading to deserialization vulnerabilities.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.