CVE-2023-52251 is a remote code execution vulnerability in provectus/kafka-ui versions 0.4.0 through 0.7.1. The vulnerability exists in the /api/clusters/local/topics/{topic}/messages endpoint, where the q parameter is insufficiently sanitized, allowing remote attackers to execute arbitrary code on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting CVE-2023-52251, a command injection vulnerability in Kafka UI versions 0.4.0 through 0.7.1. The exploit leverages the 'groovy' filter parameter in the topic section to execute arbitrary shell commands on the server without authentication. The module is weaponized, supporting customizable payloads (defaulting to a reverse shell via netcat) and automates the full attack chain: version detection, cluster discovery, topic creation, payload delivery, and cleanup. The attack is performed over HTTP (default port 8080) and interacts with several Kafka UI API endpoints. The code is written in Ruby and is structured as a standard Metasploit exploit module, making it easy to use within the Metasploit framework for penetration testing or red teaming. No hardcoded IPs or domains are present; all endpoints are relative to the target's base URL.
This repository provides a working exploit for CVE-2023-52251, a remote code execution (RCE) vulnerability in Provectus Kafka-UI versions 0.4.0 through 0.7.1. The vulnerability arises from unsanitized Groovy script filters, allowing attackers to inject and execute arbitrary code via the 'q' parameter in the /api/clusters/local/topics/{topic}/messages endpoint. The repository contains three main exploit scripts: 'poc.py' (Python), 'rce.js', and 'rce2.js' (JavaScript/Node.js). All scripts automate the exploitation process by discovering clusters and topics, then sending a malicious Groovy payload to the vulnerable endpoint. The payload can be a simple HTTP request (for detection) or a reverse shell (for full RCE). The exploit also leverages webhook.site for out-of-band verification. The repository is well-structured, with clear separation between code, documentation (README.md), and licensing. The exploit is operational and can be used to gain shell access to vulnerable Kafka-UI servers exposed to the network.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.