CVE-2024-28397 is an improper control of code generation vulnerability in js2py through version 0.74. The package's disable_pyimport() component can be bypassed or otherwise abused through a crafted API call, allowing arbitrary code execution and enabling escape from an intended JavaScript sandbox.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
16 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone exploit utility for CVE-2024-28397, consisting of one Python script and a README. The main file, cve-2024-28397.py, is not the exploit delivery itself but a payload generator: it accepts an attacker-controlled command string and emits JavaScript intended to be evaluated inside a vulnerable Js2Py environment. The generated JavaScript abuses exposed Python object wrappers by starting from Object.getOwnPropertyNames({}), traversing into Python type metadata via __getattribute__("__class__").__base__, recursively enumerating __subclasses__(), locating the Python warnings.catch_warnings class, and then using its _module.__builtins__ reference to recover __import__. From there it imports os and executes the supplied command with os.popen(cmd).read(), returning command output to the caller. The script supports a --compact option to emit the payload as a single line for easier injection. The README documents basic command execution examples and shows how an operator could wrap a bash reverse shell in base64 and embed it as the executed command. There are no hardcoded remote URLs or C2 endpoints in the exploit itself; network targeting is indirect and entirely dependent on the operator-supplied command. Overall, this is a real exploit/payload generator for sandbox escape to arbitrary command execution, with basic but functional operational capability.
Repository contains a minimal PoC for CVE-2024-28397 (js2py sandbox escape / command execution). Structure: (1) README.md describing the vulnerability (incomplete sandboxing around js2py.disable_pyimport()), impact, and references; (2) payload.js containing the exploit JavaScript. Exploit logic in payload.js: it abuses Python object model traversal from within js2py by obtaining __getattribute__, then walking from an object’s __class__ to its __base__ and recursively iterating __subclasses__() to find the class where __module__ == 'subprocess' and __name__ == 'Popen'. Once found, it instantiates subprocess.Popen with the command string (default 'whoami'), calls communicate() to capture stdout, decodes it as UTF-8, and returns it as a plain string (JSON-safe). Capabilities: arbitrary command execution on the js2py host process with output capture. No built-in networking, C2, persistence, or lateral movement. No hardcoded URLs/IPs/domains; the only notable observable is the executed command string ('whoami') and the targeted Python class/module names ('subprocess', 'Popen').
Repository contains a small, single-purpose payload generator for CVE-2024-28397 affecting Js2Py <= 0.74. Structure: (1) README.md describing the vulnerability, usage, and example commands (including a sample netcat reverse shell command), and (2) exploit.py, a Python 3 script that outputs a ready-to-inject JavaScript payload. Core capability: generate malicious JavaScript that escapes the Js2Py sandbox by leveraging Object.getOwnPropertyNames({}) to obtain a leaked Python object wrapper, then traverses Python’s class hierarchy (via __class__.__base__ and recursive __subclasses__() enumeration) to locate subprocess.Popen. Once found, it invokes Popen("<user-supplied command>", ...).communicate() to execute arbitrary OS commands on the host running the vulnerable Js2Py evaluation and returns the output. No direct exploitation of a network service is implemented in code; the operator must inject the generated JavaScript into a vulnerable application input path that is evaluated by Js2Py (e.g., a web form/API that calls js2py.eval_js on untrusted input). The script supports a configurable command via -c/--command (default: id) and performs minimal escaping of double quotes before substituting into the payload template.
This repository contains a working exploit for CVE-2024-28397, a sandbox escape vulnerability in js2py (<= 0.74) that allows remote code execution. The main exploit script, 'exploit.py', is a Python program that generates a JavaScript payload designed to break out of the js2py sandbox and execute arbitrary system commands on the host. The payload specifically launches a bash reverse shell, connecting back to an attacker-controlled IP and port. The exploit requires the attacker to specify the target URL (an endpoint that evaluates JavaScript using js2py), as well as the attacker's own IP and port for the reverse shell. The repository is simple, with only four files: a .gitignore, a README.md (which provides detailed usage and vulnerability information), the exploit script, and a requirements.txt listing dependencies (requests, termcolor). The exploit is operational and does not rely on any external dependencies on the target, making it practical for real-world attacks against vulnerable js2py deployments.
This repository contains an operational exploit for CVE-2024-28397, a sandbox escape vulnerability in the js2py Python library (versions < 0.74). The exploit is implemented as a single Python script (exploit.py) that automates the process of generating and delivering a malicious JavaScript payload to a vulnerable web endpoint. The payload leverages improper sandboxing in js2py to traverse Python's object hierarchy, access subprocess.Popen, and execute arbitrary shell commands. The default payload is a base64-encoded bash reverse shell that connects back to an attacker-controlled IP and port. The script requires the attacker to specify the target URL, their own IP, and a listening port. The README provides clear usage instructions and context about the vulnerability. The main attack vector is network-based, targeting HTTP endpoints that evaluate user-supplied JavaScript via js2py. The exploit is not part of a framework and is a standalone operational tool.
This repository contains a Python proof-of-concept exploit for CVE-2024-28397, a sandbox escape vulnerability in the Js2Py JavaScript interpreter. The exploit consists of two files: a README.md with detailed usage and vulnerability information, and exploit.py, the main exploit script. The script takes as arguments the target URL (an HTTP endpoint running vulnerable Js2Py code), the attacker's local IP, and a port for the reverse shell. It crafts a JavaScript payload that abuses Python's object model traversal to escape the Js2Py sandbox, locates subprocess.Popen, and executes a base64-encoded bash reverse shell command. The exploit sets up a listener on the attacker's machine to receive the shell and attempts basic PTY stabilization for interactive use. The attack vector is remote network-based, requiring the attacker to send a malicious payload to a vulnerable web endpoint. The exploit is a functional proof-of-concept and does not include advanced features or payload customization beyond the reverse shell.
This repository contains a working exploit for CVE-2024-28397, targeting js2py versions <= 0.74. The exploit consists of a single Python script (exploit.py) and a README.md with usage instructions. The exploit.py script takes as arguments the target's IP, port, and path to a vulnerable code execution endpoint (such as /run_code), as well as the attacker's IP and port for the reverse shell. It crafts a malicious JavaScript payload that, when executed by the vulnerable js2py service, uses Python's internal object model to locate and invoke subprocess.Popen, executing a reverse shell command (using busybox nc) to connect back to the attacker's listener. The exploit is operational and provides a reverse shell if the target is vulnerable and properly configured. The main attack vector is network-based, exploiting a remote code execution vulnerability via an HTTP POST request to a user-supplied endpoint.
This repository contains a working exploit for CVE-2024-28397, a remote code execution vulnerability in services using the JS2PY library to execute user-supplied JavaScript code. The exploit consists of a single Python script (exploit.py) that prompts the user for the target host, port, a command to execute, and a session token. It crafts a malicious JavaScript payload that abuses JS2PY's Python object exposure to traverse Python internals and locate the subprocess.Popen class, which is then used to execute arbitrary system commands on the server. The exploit sends this payload as a JSON object to the /run_code endpoint of the target via HTTP POST, using the provided session token as a cookie. The README provides a brief description and usage instructions. The exploit is operational and requires the attacker to know a valid session token and the target to be running a vulnerable JS2PY service with the /run_code endpoint exposed.
This repository provides operational exploit scripts for CVE-2024-28397, a critical sandbox escape vulnerability in the js2py Python library. The exploit enables remote code execution by abusing Python object introspection from within JavaScript code executed by js2py. The repository contains two main exploit scripts: a Go implementation (exploit.go) and a Bash implementation (exploit.sh). Both scripts prompt the user for the target URL (the endpoint running vulnerable js2py code), the attacker's IP, and a port for the reverse shell. They generate a base64-encoded bash reverse shell payload, embed it in a JavaScript snippet that escapes the js2py sandbox, and send it to the target endpoint via HTTP POST. If the target is vulnerable, it will execute the payload and connect back to the attacker's machine, granting a shell. The README provides detailed technical background, usage instructions, and references. The exploit is operational, requiring only knowledge of a vulnerable endpoint and network access to the target.
This repository contains a working exploit for CVE-2024-28397, a critical vulnerability in the js2py Python library (<= 0.74) that allows sandbox escape and remote code execution. The exploit is implemented in a single Python script (exploit.py), which generates a malicious JavaScript payload designed to be executed by a vulnerable js2py endpoint. The payload leverages Python object introspection from within JavaScript to locate and invoke subprocess.Popen, executing a base64-encoded bash reverse shell command. The exploit requires the attacker to specify the target endpoint (typically a web application's code execution API), their own IP address, and a listening port for the reverse shell. The README provides detailed usage instructions, including example commands and detection/mitigation advice. The main attack vector is network-based, targeting web services that expose js2py code execution endpoints. The repository is operational and provides a real, working exploit with a customizable payload.
This repository provides a proof-of-concept exploit for CVE-2024-28397, a remote code execution vulnerability in pyload-ng due to insecure use of js2py. The repository contains two files: a README.md with detailed usage instructions and vulnerability background, and poc.py, a Python script that automates the exploitation process. The exploit works by registering and logging in as a user on the target pyload-ng instance, then sending a specially crafted JavaScript payload to the /run_code endpoint. This payload escapes the js2py sandbox and uses Python's subprocess.Popen to execute a reverse shell command, connecting back to the attacker's machine. The exploit requires the attacker to have a listener (such as netcat) running to receive the shell. The main attack vector is network-based, targeting accessible HTTP endpoints on the vulnerable server. The code is a functional proof-of-concept and does not include advanced features or payload customization beyond the reverse shell.
This repository contains an operational exploit for CVE-2024-28397, a sandbox escape vulnerability in the js2py Python library (<= v0.74). The exploit is implemented in PHP (exploit_js2py.php) and is designed to target a Python web application that exposes a vulnerable js2py endpoint over HTTP. The exploit works by sending a crafted JavaScript payload that escapes the js2py sandbox and executes arbitrary Python code, ultimately running a bash reverse shell command to connect back to the attacker's listener. The attacker must provide the target's IP, port, endpoint URI, and their own listener IP and port. The README.md provides background, usage instructions, and technical details. The exploit is not part of a framework and is a standalone PHP script. The main attack vector is network-based, targeting a web-exposed endpoint. The payload is a bash reverse shell, and the exploit is operational, requiring minimal configuration to use against a vulnerable target.
This repository provides a detailed analysis and proof-of-concept (PoC) exploit for CVE-2024-28397, a sandbox escape vulnerability in the js2py Python package (<=0.74). The vulnerability allows attacker-supplied JavaScript code, when evaluated by js2py, to escape the intended JS sandbox and access Python internals. By leveraging Python's object model and the way js2py wraps Python objects, the exploit locates the subprocess.Popen class and executes arbitrary shell commands on the host system. The main exploit logic is contained in 'Proof of Concept.py', which demonstrates the attack by attempting to read '/etc/passwd' and launch calculator applications. The repository also includes a patch (patch.txt) and a Python script (fix.py) to mitigate the vulnerability by ensuring that getOwnPropertyNames returns a list instead of a dict_keys object, preventing the escape. The README and analysis.md files provide in-depth technical background, affected products, and safe usage instructions. The exploit is a PoC and does not include weaponized or automated attack code, and the PoC is sanitized to avoid accidental misuse. The main attack vector is remote code execution via malicious JavaScript processed by js2py in a Python environment, typically in web scraping or API parsing scenarios.
This repository contains a Python proof-of-concept exploit for CVE-2024-28397, a remote code execution vulnerability in js2py (<= v0.74). The main file, 'CVE-2024-28397-RCE.py', allows an attacker to send a specially crafted JavaScript payload to a vulnerable js2py server endpoint (such as '/run_code' on port 8000). The payload abuses Python internals exposed by js2py to locate the subprocess.Popen class and execute arbitrary system commands. By default, the script can establish a reverse shell to the attacker's machine, but it also supports running custom commands. The exploit requires the attacker's knowledge of the target's IP address and the code execution endpoint path. The README provides usage instructions and requirements, including the need for a netcat listener to catch the reverse shell. No hardcoded IPs or domains are present; the target endpoint is specified at runtime.
This repository contains a single Metasploit module targeting Pyload (<=0.5.0b3.dev85) with js2py (<=0.74), exploiting two vulnerabilities: CVE-2024-39205 (Pyload RCE) and CVE-2024-28397 (js2py sandbox escape). The exploit leverages a flaw in the /flash/addcrypted2 API endpoint, which is intended to be accessible only from localhost, but can be accessed remotely by manipulating the Host header. The module crafts a malicious JavaScript payload that escapes the js2py sandbox, allowing arbitrary command execution on the host. The exploit supports both direct command execution and staged payload delivery (dropper), and is weaponized for use within the Metasploit framework. The only file present is a Ruby module, structured according to Metasploit conventions, and includes all logic for vulnerability checking, payload generation, and exploitation. No external endpoints or IPs are hardcoded beyond the localhost reference for the Host header. The module is suitable for operational use against vulnerable Pyload installations.
This repository demonstrates a sandbox escape and remote code execution (RCE) vulnerability in the Python package js2py (<=0.74) when running under Python 3 (excluding 3.12+). The exploit leverages a flaw in the handling of JS built-in objects, specifically the return value of Object.getOwnPropertyNames, which allows an attacker to obtain a reference to a Python object (PyObjectWrapper) from JavaScript code. By chaining attribute accesses, the attacker can reach Python's subprocess.Popen and execute arbitrary shell commands on the host. The repository contains: - README files (English and Chinese) explaining the vulnerability, affected products (js2py, pyload, cloudscraper, lightnovel-crawler), and exploitation steps. - analysis_en.md and analysis_zh.md providing a deep technical dive into the vulnerability and exploitation method. - poc.py, a proof-of-concept script that executes a malicious JavaScript payload via js2py, demonstrating command execution (reading /etc/passwd and launching calculator apps). - fix.py and patch.txt, which provide a dynamic and static patch for js2py to mitigate the vulnerability by converting dict_keys to a list in the vulnerable function. - affected_version_test.txt, which documents successful exploitation across multiple Python versions. - requirements.txt specifying js2py as a dependency. The main attack vector is network-based: an attacker can supply malicious JavaScript to a target system that uses js2py to evaluate untrusted JS (e.g., via web scraping or API). The exploit is a proof-of-concept and does not include a weaponized, customizable payload, but demonstrates full RCE capability.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An arbitrary-code-execution and sandbox-escape vulnerability in js2py's disable_pyimport() component affecting js2py through version 0.74. The referenced plugin states that exploits are available, including use with Metasploit in a Pyload RCE chain.
A sandbox escape vulnerability in js2py <= 0.74 that allows unsafe JavaScript execution, potentially leading to remote code execution if user input is not properly sanitized.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.