CVE-2024-2044 is a path traversal and unsafe deserialization vulnerability in pgAdmin 4 versions up to and including 8.3. The vulnerability exists in the session handling code, where user session data is deserialized insecurely. On Windows, an unauthenticated attacker can exploit this by loading and deserializing remote pickle objects, leading to arbitrary code execution. On POSIX/Linux systems, exploitation requires authentication, but still allows an attacker to upload and deserialize malicious pickle objects, resulting in code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains one executable Python 3 exploit, CVE-2024-2044.py, and an Indonesian-language README describing setup, prerequisites, and mitigation. The standalone script targets CVE-2024-2044 in pgAdmin 4 server-mode installations on Linux/POSIX through an authenticated web attack chain. It logs in using supplied credentials, extracts CSRF tokens from HTML, initializes Storage Manager, and uploads a randomly named malicious pickle file. It then sends a separate request to /login with a crafted pga4_session cookie containing a traversal path into the authenticated user's storage directory. The intended vulnerable session manager loads the attacker-controlled file and unsafely deserializes it with pickle, executing embedded Python. The executed payload writes a target-side temporary script and starts a detached TCP reverse shell to operator-controlled LHOST:LPORT. The repository is a functional operational PoC rather than a scanner or detection-only tool; it does not belong to a recognized exploit framework. The README states that pgAdmin 4.8.4 fixes the issue.
This repository contains a single Metasploit module (Ruby) that exploits a path traversal and unsafe deserialization vulnerability (CVE-2024-2044) in pgAdmin versions <= 8.3. The exploit allows remote code execution by tricking pgAdmin into loading a malicious, pickled Python object. The module supports two exploitation techniques: (1) Authenticated exploitation, where valid credentials are used to upload a payload via the file management plugin and trigger deserialization; (2) Unauthenticated exploitation (Windows only), where an SMB server is started by the attacker and the target is tricked into loading the payload via a UNC path. The module interacts with several HTTP endpoints on the target (such as /authenticate/login, /file_manager/init, /file_manager/filemanager/<trans_id>/, and /login) and, for unauthenticated attacks, exposes an SMB endpoint. The payload is a serialized Python object that executes arbitrary code. The exploit is weaponized, as it is part of the Metasploit framework and supports customizable payloads. The repository is well-structured, containing only the exploit module, and is intended for use within Metasploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.