CVE-2023-22496 is a command injection vulnerability in Netdata Agent. When an alert is triggered, the function health_alarm_execute is called, which enqueues a command via spawn_enq_cmd. The command arguments, including registry_hostname, are not sanitized. An attacker able to establish a streaming connection can supply a crafted registry_hostname in health data, leading to arbitrary command execution as the Netdata Agent user.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
netdata). This can lead to full compromise of the agent's environment and may be leveraged for privilege escalation if other vulnerabilities exist.If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a self-contained proof-of-concept for CVE-2023-22496, an OS command injection flaw in Netdata Agent versions before 1.37.0. The main exploit logic is in `exploit.py`, a Python script that accepts an arbitrary shell command, embeds it into a malicious `registry hostname` payload (`x' & CMD & #`), overwrites `config/parent_netdata.conf`, force-recreates the `agent_parent` Docker container, waits for a health alarm to fire, and then checks for evidence of execution. The exploit achieves command execution as the `netdata` user by abusing Netdata's alarm notification path, where `registry_hostname` is inserted unsafely into a shell command executed via `/bin/sh`. Repository structure supports reproducible lab exploitation: `Dockerfile` builds vulnerable Netdata v1.36.1 from source into a runtime image; `docker-compose.yaml` creates a 3-node streaming chain (`agent_child -> agent_middle -> agent_parent`) to demonstrate propagation of attacker-controlled hostname data through Netdata streaming; the `config/` directory contains fixed GUIDs and per-node Netdata/streaming configs. The parent node exposes port 21000->19999 and the middle node exposes 21001->19999 for verification. The exploit is operational rather than just theoretical because it automates payload injection, container restart, service health checking, and post-exploitation verification. It is not merely a detector: it is designed to trigger real command execution, including file creation and reverse shell payloads.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.