Cargo, the Rust package manager, prior to version 0.72.2 (bundled with Rust prior to 1.71.1), failed to respect the system umask when extracting crate archives on UNIX-like systems. This oversight could result in files being extracted with permissions that allow write access to other local users. If a crate archive contained files with overly permissive permissions, a local attacker could modify the source code after extraction but before compilation, leading to potential code execution under the victim's context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a full exploit chain for CVE-2023-38497, a local privilege escalation vulnerability in Cargo (Rust's package manager) version 1.7.0. The exploit targets writable crate source files in the local Cargo registry (~/.cargo/registry/src/), allowing an attacker with group or user write access to inject arbitrary Rust code into a dependency used by a target project. The repository includes: - A mock shell (src/main.rs) that orchestrates the attack pipeline: analyzing the target project for vulnerable dependencies, integrating a payload into a selected method, and finalizing the injection. - Bash scripts (shell-scripts/vanalyzer/) for analyzing the target project and identifying exploitable methods in writable crate files. - A payload module (src/payload.rs) that provides a reverse shell payload, which is injected into the target method. The reverse shell connects to localhost:4444, granting the attacker a shell as the victim user when the target project is built or run. - Integration and compilation utilities (src/compilation.rs) to test the injected code before finalizing the attack. - Example and test files demonstrating the attack process and verifying successful payload injection. The exploit is operational and automates the process of identifying, injecting, and testing a reverse shell payload in a real-world attack scenario. The main attack vector is local, requiring the attacker to have access to a user account with write permissions to the target crate files. The exploit does not target remote systems directly but leverages local misconfigurations to escalate privileges or gain shell access to other users.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.