Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the JonesFaithfulTransformation.from_transformation_str() method within the pymatgen library prior to version 2024.2.20. This method insecurely utilizes eval() for processing input, enabling execution of arbitrary code when parsing untrusted input. Version 2024.2.20 fixes this issue.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a functional exploit for CVE-2024-23346, a remote code execution vulnerability in the pymatgen Python library, as used in a web application context (specifically, the Chemistry retired Hack The Box machine). The main file, CVE-2024-23346-exploit.py, is a Python script that automates the exploitation process: it logs into the target web application, uploads a malicious CIF file crafted to exploit the vulnerability, and triggers the parsing of this file to achieve arbitrary command execution on the server. The exploit requires valid credentials and network access to the target's web interface. The script also sets up a listener to receive command output via netcat, allowing interactive command execution. The endpoints targeted include /login, /upload, /dashboard, /structure/<id>, and /delete_structure/<id>. The repository is well-structured, with a single exploit script and a README providing usage instructions and context. The exploit is operational and demonstrates real-world impact by providing remote shell access to the attacker.
This repository is a Rust-based exploit for CVE-2024-23346, targeting a code injection vulnerability in the Pymatgen CIF Parser. The exploit automates the process of authenticating to a vulnerable web application, uploading a malicious CIF file containing a Python code injection payload, and triggering its parsing to achieve remote code execution. The main logic resides in 'src/main.rs', which handles login, file upload, payload generation, and the setup of a TCP listener to receive a reverse shell from the target. The exploit is interactive, allowing the attacker to execute arbitrary shell commands on the target system, with command output sent back over a dynamically chosen TCP port. The repository includes a sample payload file ('file/poc.cif') and a README with usage instructions. The exploit is operational and provides a working reverse shell if the target is vulnerable and properly configured.
This repository contains a single Python proof-of-concept exploit (CVE-2024-23346.py) and a README. The exploit targets a remote code execution vulnerability in pymatgen (as described in advisory GHSA-vgv8-5cpj-qj2f). The exploit requires valid credentials to log in to the target web application. It crafts a malicious CIF file with a payload that, when processed by the server, executes a bash reverse shell command, connecting back to the attacker's machine. The script automates the login, file upload, and payload triggering process, and can optionally save the malicious CIF file locally. The attack vector is network-based, requiring access to the target's web interface. The endpoints involved are /login, /upload, /dashboard, and /structure/{uuid}. The exploit is a functional proof-of-concept and does not include advanced features or payload customization beyond the reverse shell.
This repository contains a Python exploit script (exploit.py) targeting CVE-2024-23346, a code execution vulnerability in a web application running on port 5000. The exploit requires valid credentials to log in to the application. After authentication, it uploads a specially crafted CIF file via the /upload endpoint. The file exploits a vulnerability in the application's file parsing logic, allowing arbitrary shell command execution. The exploit script provides an interactive shell-like interface, sending commands to the target and receiving output via a TCP connection to the attacker's specified host and port. The script also performs cleanup by deleting structures in the application. The README provides basic usage instructions. The main endpoints targeted are /login, /dashboard, /delete_structure/<id>, /upload, and /structure/<id> on the target server. The exploit is operational and provides real command execution capabilities, but is not part of a larger framework.
This repository provides a proof-of-concept exploit for CVE-2024-23346, targeting the pymatgen library's handling of Crystallographic Information Files (CIF). The exploit is delivered as a specially crafted CIF file, with a malicious payload embedded in the '_space_group_magn.transform_BNS_Pp_abc' field. When processed by a vulnerable pymatgen instance, this payload executes arbitrary system commands. The provided example demonstrates a reverse shell to 10.10.10.10:4444 using /bin/bash. The repository contains only a LICENSE and a README.md, with the exploit code and usage instructions in the README. No executable code files are present; the exploit is intended to be used by modifying and submitting the malicious CIF file to a target system. The repository is educational and references several external resources for further information.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.