CVE-2022-42889 affects Apache Commons Text versions 1.5 through 1.9. Its default variable-interpolation configuration resolves expressions in the form ${prefix:name} through StringLookup implementations. The default lookup set includes script, which evaluates expressions through the JVM javax.script engine, as well as dns and url, which respectively perform DNS resolution and retrieve values from URLs. Interpolating attacker-controlled values through the default configuration can invoke these unsafe lookups, resulting in arbitrary code execution or unintended remote-server communication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
14 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (13 hidden).
Small standalone Python proof-of-concept exploit for CVE-2022-42889 (Apache Commons Text 'Text4Shell'). The repository contains only two files: a README and one executable Python script. The script accepts three arguments: target host[:port], callback IP, and callback port. It builds a JavaScript-based Commons Text interpolation payload that invokes java.lang.Runtime.getRuntime().exec() to run a bash reverse shell command. The exploit then iterates through several likely parameter names (query, search, q, text, input, name) and multiple request styles to maximize compatibility with unknown target applications: GET /search with payload in the query string, POST /search with payload in the URL query string, POST /search with application/x-www-form-urlencoded body, and POST /search with JSON body. It prints HTTP response codes and basic response-body hints to help identify accepted parameters, but its main purpose is exploitation rather than pure detection. The exploit is operational but basic: payload and target path are hardcoded, there is no TLS support, no authentication handling, and no automatic listener setup. Main capability is unauthenticated remote code execution leading to a reverse shell, assuming the vulnerable application exposes the expected /search endpoint and the host can reach the attacker over TCP.
This repository is a small Java/Maven Spring Boot demo application intentionally built to demonstrate exploitation of SnakeYAML unsafe deserialization (CVE-2022-1471) and then show remediation via Seal Security. It is not just documentation: the core exploit behavior is implemented in application code, primarily in src/main/java/io/sealsecurity/demo/controller/HelloController.java. Repository structure: DemoApplication.java is the Spring Boot entry point; HelloController.java contains the vulnerable web endpoint and exploit logic; DataService.java contains additional examples of vulnerable dependency usage (Commons Text, SnakeYAML, Log4j) but is not the main exploit path; application.properties sets the app name and port 8080; DemoApplicationTests.java provides basic tests. Supporting files include pom.xml with intentionally vulnerable dependency versions, GitHub Actions workflows that build/run the app and expose it via ngrok, a Jenkinsfile showing CI integration, and .seal-actions.yml mapping vulnerable dependencies to sealed versions. Main exploit capability: the root route '/' accepts a 'name' parameter over GET or POST and passes it directly to new Yaml().load(name). If the input contains a YAML global tag such as '!!javax.script.ScriptEngineManager []', vulnerable SnakeYAML 1.33 will instantiate the attacker-specified Java type. The controller treats this as an exploit attempt, returns a 'You've been pwned' HTML page, and asynchronously calls Runtime.getRuntime().halt(1) after a short delay, killing the JVM. This makes the exploit operational as a remote unauthenticated denial-of-service demonstration and a proof of arbitrary type instantiation. The code does not include a full gadget chain for arbitrary code execution, but the README explicitly frames it as the object-injection primitive behind RCE. The exploit is web/network-based, requiring only HTTP access to the application. Fingerprintable targets include the '/' endpoint, the 'name' parameter, localhost:8080 for local testing, and a hardcoded public ngrok hostname used in CI demos. The workflows also contain external infrastructure references for ngrok and Seal CLI downloads. Overall, this is a legitimate exploit/demo repository for CVE-2022-1471 with an intentionally vulnerable application and CI automation to demonstrate both exploitation and remediation.
Small standalone Python proof-of-concept for CVE-2022-42889 (Text4Shell). The repository contains only a README and one executable script, text4shell.py. The script uses argparse to accept a target base URL, an operation mode, and either a command (rce mode) or a secondary URL (ssrf mode). It URL-encodes a Commons Text interpolation payload and appends it directly to the supplied target URL, then issues a single HTTP GET request with requests.get() and prints the response body and status code. In rce mode, it generates a script lookup payload using JavaScript to call java.lang.Runtime.getRuntime().exec(command), aiming for remote command execution on vulnerable Java applications. In ssrf mode, it generates a url lookup payload to force the target to fetch an attacker-controlled URL, enabling SSRF validation or exploitation. There is no listener, shell management, authentication bypass, scanning logic, or framework integration; the operator must already know a reachable injection point and provide the full vulnerable parameterized URL. Overall, this is an operational but basic exploit helper for web-exposed Apache Commons Text interpolation sinks.
This repository contains a Python script (text4shll.py) that exploits the CVE-2022-42889 (Text4Shell) vulnerability in Apache Commons Text versions prior to 1.10.0. The exploit works by crafting a malicious payload that leverages the vulnerable string interpolation functionality to execute arbitrary code on the target server. The payload is a Java string that, when processed by the vulnerable library, executes a bash reverse shell command, connecting back to the attacker's machine. The script takes command-line arguments for the target's IP, port, vulnerable path, parameter name, and the attacker's listener IP and port. It constructs a URL with the encoded payload and sends an HTTP GET request to the target. The README.md provides usage instructions and context. The main entry point is text4shll.py, and the only code language used is Python. The exploit is operational, requiring the attacker to set up a listener to catch the reverse shell. No hardcoded endpoints are present; all are supplied via command-line arguments.
This repository contains a Python proof-of-concept exploit for the Text4Shell vulnerability (CVE-2022-42889) in Apache Commons Text versions prior to 1.10.0. The main exploit script, 'text4shell.py', takes a target IP, a callback IP, and a callback port as arguments. It crafts a malicious payload using the '${script:...}' interpolator, which, when processed by a vulnerable Java backend, executes a bash reverse shell connecting back to the attacker's machine. The exploit sends the payload via a POST request to the target's HTTP endpoint, using the 'data' query parameter (which may need to be adjusted for different targets). The repository is structured simply, with a license, a README explaining usage and context, and the exploit script itself. The exploit is a functional PoC and does not include detection or scanning capabilities.
This repository contains a single Metasploit module: 'modules/exploits/multi/http/apache_commons_text4shell.rb', which exploits the Apache Commons Text 'Text4Shell' vulnerability (CVE-2022-42889). The exploit targets applications using vulnerable versions (1.5-1.9) of the Commons Text library with the StringSubstitutor interpolator enabled, and running on JDK versions less than 15. The module supports multiple payloads, including Java Meterpreter reverse shell, Windows/Linux droppers, and command execution for both Windows and Unix platforms. The exploit works by injecting a specially crafted string into a user-supplied HTTP parameter, leveraging the 'script' interpolator to achieve remote code execution. The module is highly weaponized, supporting automated payload staging and multiple attack vectors via HTTP GET or POST requests. The only file in the repository is a Ruby script, structured as a standard Metasploit exploit module, and includes all necessary logic for detection, exploitation, and payload delivery.
This repository is a Proof of Concept (POC) for CVE-2022-42889, also known as 'Text4Shell', a critical remote code execution vulnerability in Apache Commons Text versions 1.5 through 1.9. The repository contains a minimal Java Spring Boot web application (DockerApp.java, HelloController.java) that exposes an HTTP GET endpoint at /text4shell/attack. User input to the 'search' parameter is directly passed to StringSubstitutor.createInterpolator().replace(), making it vulnerable to malicious payloads that exploit the unsafe interpolators (such as 'script', 'dns', 'url'). The README provides step-by-step instructions to build and run the application in Docker, set up a netcat listener, and exploit the vulnerability to obtain a reverse shell on the host. The main exploit payload uses the 'script' interpolator to execute arbitrary system commands, demonstrated by spawning a reverse shell to the attacker's machine. The repository structure includes build files (pom.xml, Dockerfile), source code, and a test placeholder. No detection scripts or fake elements are present; this is a functional POC exploit for educational and testing purposes.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2022-42889 (Text4Shell), targeting Apache Commons Text versions 1.5 through 1.9. The project is a Java Spring Boot web application that demonstrates exploitation of the StringSubstitutor interpolation vulnerability. The main entry point is a web interface running on http://localhost:8081, where users can select different payloads: 1. Arbitrary command execution (e.g., creating /tmp/blop). 2. DNS-based out-of-band (OOB) interaction (for exfiltration or detection). 3. HTTP-based OOB interaction. 4. Reverse shell to a specified remote host and port. The core exploit logic is in `src/main/java/net/kvak/text4shell/controller/ExploitController.java`, which constructs malicious interpolation strings and processes them using the vulnerable StringSubstitutor. The application is containerized via Docker and can be built and run locally. The repository includes supporting files for Maven and Docker, as well as HTML templates for the web UI. This PoC is operational and demonstrates real exploitation scenarios, including command execution and network callbacks, but does not automate exploitation against remote targets.
This repository is a proof-of-concept (POC) exploit for the 'Text4Shell' vulnerability in Apache Commons Text 1.8. The Java application is built with Spring Boot and exposes an HTTP endpoint at /text4shell/attack. User input provided to the 'search' parameter is processed by Apache Commons Text's StringSubstitutor interpolator, which is vulnerable to arbitrary code execution if untrusted input is passed. The README demonstrates how to build and run the application in Docker, and how to exploit the vulnerability by injecting a payload such as '${script:javascript:java.lang.Runtime.getRuntime().exec('touch /tmp/foo')}' into the 'search' parameter, resulting in arbitrary command execution on the server. The main exploit capability is remote code execution via a network-accessible HTTP endpoint. The repository structure includes build files (pom.xml, Dockerfile), the main application code (DockerApp.java, HelloController.java), and a test placeholder. The exploit is not weaponized but serves as a clear demonstration of the vulnerability.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2022-42889, a critical vulnerability in Apache Commons Text (versions 1.5.0 to <1.10.0) that allows for arbitrary code execution, server-side HTTP requests, and DNS queries via unsafe string interpolation. The main exploit logic is implemented in 'src/main/java/com/seanwrightsec/poc/PoC.java', which prompts the user for an exploit string and uses StringSubstitutor.createInterpolator() to process it. The PoC demonstrates three main attack vectors: (1) Remote code execution via the 'script' lookup (e.g., executing system commands through JavaScript), (2) Server-side HTTP requests via the 'url' lookup, and (3) DNS queries via the 'dns' lookup. The repository includes a Dockerfile for easy setup and a README.md with detailed usage instructions and examples. The exploit is not weaponized but provides a clear demonstration of the vulnerability's impact, including the ability to execute arbitrary commands, access internal URLs, and perform DNS lookups from the vulnerable server.
This repository is a proof-of-concept exploit for CVE-2022-42889 (Text4Shell), a critical remote code execution vulnerability in Apache Commons Text versions 1.5 to 1.9. The exploit is implemented in Python (main.py) and provides an interactive CLI for the attacker. It allows scanning a target for open ports and OS information (using nmap), executing arbitrary shell commands on a vulnerable server via crafted payloads, and establishing a reverse shell (bash for Linux, PowerShell for Windows) back to the attacker's machine. The exploit works by injecting a malicious payload into a URL parameter that is processed by the vulnerable Commons Text interpolation mechanism. The payloads leverage the 'script', 'url', and 'dns' lookup features to trigger code execution. The README.md provides background on the vulnerability, usage instructions, and legal disclaimers. The main.py script is the entry point and contains all exploit logic, including payload generation, network scanning, and reverse shell setup. No hardcoded endpoints are present; the attacker supplies target URLs and listener details at runtime.
This repository is a Proof-of-Concept (PoC) for CVE-2022-42889 (Text4Shell), a critical vulnerability in Apache Commons Text versions 1.5 through 1.9. The PoC is implemented as a Spring Boot web application exposing several HTTP endpoints (/poc1, /poc2, /poc3, /message) that demonstrate different exploitation vectors: remote code execution (RCE) via the 'script' interpolator, DNS exfiltration via the 'dns' interpolator, and arbitrary URL fetching via the 'url' interpolator. The vulnerable code uses StringSubstitutor.createInterpolator() to process user-controlled input, which can be exploited if the application is running a vulnerable version of Apache Commons Text. The repository includes Dockerfiles for different Java versions, a Maven build file (pom.xml) specifying the vulnerable dependency, and Java source files implementing the exploit logic. The PoC demonstrates both Nashorn (JVM < 15) and JEXL (JVM >= 15 with commons-jexl3) script engines for RCE. The exploit can be used to execute arbitrary commands, trigger DNS lookups, or fetch remote URLs, depending on the payload provided to the endpoints.
This repository contains a proof-of-concept exploit for CVE-2022-42889 (Text4Shell), a remote code execution vulnerability in Apache Commons Text versions 1.5 through 1.9. The main exploit file, 'CVE-2022-42889.php', generates a malicious payload that leverages the vulnerable string interpolation feature to execute a reverse shell command on the target server. The payload is injected into a specified HTTP endpoint (defaulting to 'http://localhost/text4shell/attack?search={{exploit}}'), and if the target is vulnerable, it will connect back to the attacker's machine at IP 172.17.0.1 on port 1337, spawning a shell. The repository structure is simple, consisting of the exploit script and a README file that provides background and references. The exploit demonstrates operational capability, as it includes a working payload and can be adapted by changing the IP, port, and shell type.
This repository provides a proof-of-concept (PoC) exploit for CVE-2022-42889, also known as 'Text4Shell', which affects Apache Commons Text versions 1.5 through 1.9. The main exploit script (CVE-2022-42889.py) automates the process of downloading a set of payloads, customizing them to use a Burp Collaborator domain for DNS callbacks, and then uses tools like gau, qsreplace, and ffuf to fuzz target URLs with these payloads. The exploit attempts to trigger remote code execution by injecting specially crafted strings into web application parameters, leveraging the vulnerable StringSubstitutor interpolator in Commons Text. Successful exploitation is typically verified by observing DNS requests to an attacker-controlled domain (id.burpcollaborator.com). The repository is structured with a single Python exploit script, a README with technical details and manual exploitation instructions, and a license file. The exploit is a PoC and requires the target to process attacker-controlled input with the vulnerable library. No hardcoded target endpoints are present; the user must specify the target domain.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in the Apache Commons Text library, commonly known as Text4Shell.
A vulnerability in Apache Commons Text variable interpolation defaults that can enable arbitrary code execution or unintended outbound connections when untrusted input is processed.
An Apache Commons Text variable-interpolation remote code execution vulnerability.
Apache Commons Text variable-interpolation remote code execution vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.