CVE-2024-23334 is a directory traversal vulnerability in aiohttp static-resource handling. aiohttp web-server applications that configure a static route with follow_symlinks=True do not validate that a requested file resolves within the configured static root directory. An attacker can use traversal input to cause the server to read files outside that root, including when no symbolic links are present. aiohttp 3.9.2 fixes the issue.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
9 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository contains a minimal Bash proof-of-concept for CVE-2024-23334 (aiohttp static route path traversal). Structure: (1) README.md with brief usage notes and screenshots; (2) exploit.sh which takes three arguments (host, port, file) and issues a crafted HTTP GET using curl --path-as-is to prevent client-side path normalization. The exploit concatenates a static route folder (default 'static'), a long '../' traversal string, and a user-supplied file path to attempt arbitrary file read from the server. Notable issue: the script includes a status check using curl against "$URL:$PORT" but URL/PORT variables are undefined (should likely be $host/$port), so the check may not work as intended; however, the core exploit request is the final curl to http://$host:$port/$folder/$string/$file.
Repository contains a single Python proof-of-concept exploit script for CVE-2024-23334 (aiohttp path traversal) plus a README and requirements. - Structure: - CVE-2024-23334.py: CLI PoC that takes <target> <file> [port] and performs an HTTP GET to a presumed static route /assets with a traversal sequence to read arbitrary files. - README.md: Explains the vulnerability and notes it was used for HTB Chemistry; states the vulnerable condition is aiohttp static file serving with follow_symlinks=True. - requirements.txt: pwn, termcolor, requests. - Exploit behavior/capabilities: - Network-based arbitrary file read: constructs path "/assets/../../../../../" + user-supplied file (e.g., /etc/passwd) and requests it via http.client.HTTPConnection. - Minimal validation: first checks reachability with requests.get("http://{target}") and then sends the traversal request; prints response body decoded with errors ignored. - No post-exploitation/persistence: does not write files, execute commands, or open shells; it only retrieves and displays file contents. - Notable implementation details: - Assumes the vulnerable static route is /assets (hardcoded), which is a fingerprintable indicator and may need adjustment for other deployments. - Port defaults to 80; the script passes port as a string to HTTPConnection (works in many cases but is slightly sloppy). - Uses pwntools logging for output formatting; termcolor for banner styling.
This repository provides a Bash proof-of-concept exploit for CVE-2024-23334, a Local File Inclusion (LFI) vulnerability in the aiohttp Python web server framework (versions prior to 3.9.2). The exploit automates directory traversal attacks against misconfigured static file routes, allowing an attacker to read arbitrary files from the server's filesystem. The main script, 'lfi_aiohttp.sh', takes a file path as input and constructs HTTP requests with increasing levels of '../' traversal to access the specified file. The script uses curl to interact with the target server, whose URL and static file route must be set in the script variables. The README provides detailed usage instructions, configuration notes, and an example output showing the dumping of /etc/passwd. The exploit is network-based, requiring access to the vulnerable server, and is intended for educational or authorized penetration testing purposes only. No hardcoded payloads or weaponization features are present; the script is a straightforward POC for file read via LFI.
This repository contains a proof-of-concept exploit for CVE-2024-23334, targeting a directory traversal vulnerability in aiohttp servers that serve static files. The exploit is implemented as a Bash script ('exploit.sh') which takes three arguments: the target host, port, and the file to retrieve. It constructs a URL with a traversal string to access files outside the intended static directory. The script first checks if the server is accessible, then attempts to retrieve the specified file using a crafted HTTP request. The README provides usage instructions and notes that the static folder may need to be adjusted depending on server configuration. No hardcoded endpoints are present; the script is designed to be run against user-specified targets. The exploit demonstrates the vulnerability but does not provide weaponized or automated post-exploitation capabilities.
This repository is a proof-of-concept (PoC) exploit for CVE-2024-23334, a path traversal vulnerability. The main file, 'exploit.py', is a Python script that automates sending HTTP requests with crafted payloads to a web service running at 'http://localhost:8081/assets/'. The script attempts to access files outside the intended directory by prepending '../' sequences to the file path (e.g., 'root/root.txt'). It uses the 'curl' command with the '--path-as-is' option to avoid URL normalization, and iterates through increasing numbers of '../' to bypass directory restrictions. The exploit checks for a successful HTTP 200 response to determine if the file was accessed. The repository also includes a 'requirements.txt' for Python dependencies ('requests' and 'colorama'), though the exploit itself uses 'subprocess' to call 'curl' rather than the 'requests' library. The README provides usage instructions and context. No hardcoded credentials or external IPs are present; the exploit targets a local or test instance by default. The structure is simple, with a single exploit script, a README, and a requirements file.
This repository is a Proof of Concept (PoC) for CVE-2024-23334, a Local File Inclusion (LFI) vulnerability in aiohttp (version 3.9.1). The repository contains: - 'server.py': A minimal aiohttp server configured to serve static files from a 'static/' directory with 'follow_symlinks=True', exposing the LFI vulnerability. - 'exploit.py': The main exploit script, which attempts to retrieve '/etc/passwd' from a target server by sending GET requests to '/static/../../.../etc/passwd' with increasing directory traversal depth. It stops when a successful (HTTP 200) response is received and prints the file contents. - 'aiohttp.yaml': A nuclei scanner template for automated detection of the LFI vulnerability, using similar traversal payloads and matching on the presence of 'root:' in the response body. - 'requirements.txt': Specifies 'aiohttp==3.9.1' for the PoC server. - 'README.md': Provides setup instructions, usage examples, and screenshots. The exploit demonstrates the ability to read arbitrary files from the server filesystem via HTTP requests, specifically targeting the '/etc/passwd' file as a proof. The PoC is intended for educational and testing purposes, and the vulnerability is exploitable over the network on any aiohttp server with a similar static file configuration.
This repository is a proof-of-concept (PoC) exploit for CVE-2024-23334, a path traversal vulnerability in the Python aiohttp library (versions <= 3.9.1). The repository contains a minimal vulnerable server (server.py) that serves static files using aiohttp's add_static method, and an exploit script (exploit.sh) that attempts to read arbitrary files from the server by exploiting the path traversal flaw. The exploit.sh script iteratively crafts HTTP requests with increasing numbers of '../' sequences in the path to traverse directories and access files such as /etc/passwd. The server is configured to run on localhost:8081, and the exploit targets this endpoint. The repository also includes a requirements.txt specifying the vulnerable aiohttp version and a static test file. The exploit demonstrates the vulnerability but does not provide weaponized or automated post-exploitation capabilities.
This repository contains a proof-of-concept exploit for CVE-2024-23334, a Local File Inclusion (LFI) and path traversal vulnerability in aiohttp versions <= 3.9.1. The exploit is implemented in Python (exploit.py) and allows an attacker to read arbitrary files from a vulnerable aiohttp server by abusing the static file serving mechanism when 'follow_symlinks=True' is set. The exploit works by sending HTTP GET requests with crafted paths containing multiple '/../' sequences to traverse directories and access files outside the intended static directory. The README.md provides usage instructions, background on the vulnerability, and references. The exploit requires the attacker to specify the target URL, the file to read, and the static directory route. The main entry point is exploit.py, which is a standalone script and not part of any exploit framework.
This repository contains a proof-of-concept exploit for CVE-2024-23334, a local file inclusion (LFI) vulnerability in aiohttp 3.9.1 when the 'follow_symlinks' option is enabled. The exploit is implemented as a Bash script ('lfi.sh') that takes a target URL and a file path as arguments. It attempts to read arbitrary files from the target server by constructing URLs with increasing numbers of '../' directory traversal sequences and appending the user-supplied file path. The script uses curl to send requests and checks for HTTP 200 responses to determine if the file was successfully read. The README provides usage instructions and describes the vulnerability. No hardcoded endpoints are present; the script is generic and requires user-supplied targets and file paths. The exploit demonstrates the vulnerability but does not provide weaponized or automated post-exploitation capabilities.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Directory-traversal vulnerability in aiohttp related to the follow_symlinks functionality.
Directory-traversal vulnerability in aiohttp's follow_symlinks functionality.
A directory-traversal vulnerability in aiohttp related to use of follow_symlinks.
An aiohttp HTTP-parser vulnerability that can enable HTTP request smuggling in certain proxy deployment environments and trigger unhandled exceptions leading to excessive application-server or logging resource consumption. It resulted from an incomplete fix for CVE-2023-47627.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.