Remote command execution vulnerability in Apache HugeGraph-Server affecting versions 1.0.0 up to (but not including) 1.3.0 when running on Java 8 or Java 11. The issue is described as command execution via Gremlin, enabling an attacker to achieve RCE against the HugeGraph-Server deployment.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone exploit PoC for CVE-2024-27348 affecting Apache HugeGraph Server. It contains two files: a README describing the vulnerability, usage, and rationale, and a single Python entry-point script, exploit.py, which performs the attack. The exploit is not part of a larger framework. The Python script uses requests to send an HTTP POST request to the target's /gremlin endpoint with a JSON body containing a gremlin-groovy payload. The embedded Groovy/Java code uses reflection to modify the current thread name to "BypassThread", apparently to evade HugeGraph's sandbox logic that blocks execution from specific worker thread names. It then constructs a java.lang.ProcessBuilder instance with arguments ["/bin/bash", "-c", attacker_command], starts the process, waits for it to finish, reads stdout through java.util.Scanner, and returns the output in the API response. This makes the exploit a non-blind RCE PoC rather than a simple fire-and-forget command launcher. Main capabilities include unauthenticated remote command execution, sandbox bypass via thread renaming, reliable handling of complex shell commands, and retrieval of command output from the server. The README also documents use for reverse shells, though the script itself simply executes whatever command string the operator supplies. The code disables TLS verification warnings and sends requests with a 15-second timeout. Fingerprintable targets and artifacts are limited and straightforward: the primary network target is the /gremlin HTTP endpoint on a vulnerable HugeGraph server; the target-side shell path is /bin/bash; and the exploit references Java classes java.lang.Thread, java.lang.ProcessBuilder, and java.util.Scanner as part of the payload logic. Overall, this is a concise but functional operational PoC for exploiting HugeGraph Gremlin API RCE.
Repository contains a small Python exploitation toolkit for CVE-2024-27348 targeting Apache HugeGraph-Server (Gremlin Server). Structure: (1) exploit.py is the main exploit that performs a network POST to the Gremlin endpoint at `${target}/gremlin` with a crafted Gremlin-Groovy script. The script uses Java reflection to create a `java.lang.ProcessBuilder` and execute a bash command that decodes a base64-encoded setup script. That setup script writes a PHP web shell to `/tmp/shell.php` and starts the PHP built-in server bound to `0.0.0.0:4444`, effectively exposing an HTTP command execution endpoint. (2) bind_shell.py is a companion interactive client that repeatedly issues HTTP GET requests to `http(s)://<host>:4444/?cmd=<urlencoded>` and prints the response, providing a pseudo-shell. requirements.txt lists dependencies (primarily `requests`; other entries are standard library modules). Overall purpose: provide an end-to-end exploitation chain from Gremlin injection/RCE to persistent interactive command execution via an HTTP-accessible PHP web shell.
This repository provides a proof-of-concept exploit for CVE-2024-27348. It contains two main Python scripts: 'exploit.py' and 'bindShell.py'. The 'exploit.py' script targets a vulnerable /gremlin endpoint on a remote server, exploiting it by sending a Gremlin-Groovy payload that writes a PHP web shell to /tmp/shell.php and starts a PHP server listening on port 4444. The payload is base64-encoded and executed via bash on the target. The 'bindShell.py' script acts as a remote shell client, connecting to the PHP web shell via an Ngrok tunnel, allowing the attacker to send commands and receive output over HTTP. The repository is structured for educational and research purposes, as stated in the LICENSE.md. No detection scripts are present; the code is a functional exploit that provides remote code execution capabilities on a vulnerable target.
This repository contains a single Metasploit module targeting Apache HugeGraph Server versions prior to 1.3.0, exploiting CVE-2024-27348. The exploit leverages a vulnerability in the Gremlin Groovy script execution endpoint ('/gremlin') to bypass sandbox restrictions and achieve remote code execution (RCE) on the server. The module is written in Ruby and follows standard Metasploit conventions, using the HttpClient mixin to interact with the target. The exploit works by sending a specially crafted Java payload (delivered as a Gremlin script) via a POST request to the '/gremlin' endpoint, which results in arbitrary command execution on the server. The module includes a version check to ensure the target is vulnerable and allows for customizable payloads, making it operational and suitable for real-world exploitation. The only fingerprintable endpoint is the '/gremlin' HTTP path, which is the main attack surface. The repository is structured as a typical Metasploit exploit module and is intended for use within the Metasploit Framework.
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-27348, a remote code execution vulnerability in Apache HugeGraph Server. The main file, CVE-2024-27348.py, is a Python script that targets the /gremlin HTTP endpoint of a HugeGraph server. It sends specially crafted Gremlin-Groovy scripts that leverage Java reflection and ProcessBuilder to execute arbitrary system commands on the server. The script can target a single server or multiple servers listed in a file, and outputs the result of the executed command. The README provides setup instructions for running a vulnerable HugeGraph instance using Docker or docker-compose, and gives an example of how to use the exploit. The exploit is network-based, requiring access to the target's /gremlin endpoint. No detection or fake code is present; this is a functional PoC exploit.
This repository provides an operational exploit for CVE-2024-27348, a remote code execution (RCE) vulnerability in Apache HugeGraph server versions 1.0.0 before 1.3.0. The main script, CVE-2024-27348_Scanner.py, is a Python tool that targets the /gremlin endpoint of HugeGraph servers. It sends specially crafted Gremlin Groovy payloads that use Java reflection to execute system commands (ping, curl, wget, host) on the target server, with the attacker's domain as an argument. This allows the attacker to verify RCE by observing outbound requests from the target to their own infrastructure. The script supports both single-target and multi-target modes (via targets.txt). The README provides usage instructions and context. The exploit is operational, as it automates exploitation and verification, but does not provide a fully weaponized or post-exploitation payload.
This repository provides a proof-of-concept (PoC) exploit and a detection script for CVE-2024-27348, a critical remote code execution vulnerability in Apache HugeGraph Server (versions 1.0.0 before 1.3.0). The exploit leverages the Gremlin traversal language interface, sending specially crafted Gremlin queries via HTTP POST requests to the /gremlin endpoint. These queries use Java reflection to bypass security restrictions and execute arbitrary system commands on the server. The main exploit script (exploit.py) allows the attacker to specify a command and a target (or a list of targets), while the detection script (detect.py) triggers an outbound request (e.g., curl to an attacker-controlled domain) to verify if the vulnerability exists. The repository is structured with two main Python scripts (exploit.py and detect.py), a README with usage instructions and vulnerability details, and a LICENSE file. The exploit is network-based, targeting exposed HugeGraph servers, and does not require authentication if the server is misconfigured. No hardcoded IPs or domains are present; the attacker supplies these at runtime.
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-27348, a remote code execution (RCE) vulnerability in Apache HugeGraph Server. The main exploit script, CVE-2024-27348.py, is a Python program that targets the /gremlin HTTP endpoint of HugeGraph Server. It allows an attacker to execute arbitrary OS commands on the server by sending specially crafted JSON payloads that inject Groovy code via the Gremlin query language. The exploit does not require authentication and can target either a single server (via the -t/--target argument) or multiple servers listed in a file (via the -f/--file argument). The payload leverages Java reflection and ProcessBuilder to execute commands. The repository also includes a README with usage instructions, a requirements.txt listing dependencies (argparse, requests), and a LICENSE file. The exploit is classified as a proof-of-concept and demonstrates unauthenticated RCE via network access to the vulnerable endpoint.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.