A Cross Site Scripting (XSS) vulnerability exists in Advanced REST Client version 17.0.9. The vulnerability is present in the New Project function, specifically in the handling of the 'edit details' parameter, which fails to properly sanitize user-supplied input. This allows a remote attacker to inject and execute arbitrary scripts in the context of the application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-25503, a stored Cross-Site Scripting (XSS) vulnerability in the Advanced REST Client (ARC) desktop application version 17.0.9. The repository contains two files: a detailed README.md explaining the vulnerability, exploitation steps, and impact, and an xss_script.html file containing example XSS payloads. The exploit works by embedding malicious JavaScript in the project description field of a new ARC project, exporting the project, and having a victim import and open the project file. When the victim opens the project in ARC, the XSS payload executes, allowing the attacker to leak information (such as the current document location) or redirect the victim to an external phishing site (e.g., http://naver.com). The attack vector is local in the sense that the victim must import a malicious file, but the impact is remote code execution within the context of the ARC app. The repository does not contain any detection scripts or fake exploits, and the payload is a standard XSS JavaScript snippet. The only fingerprintable endpoints are the vendor's website and the phishing redirect URL.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.