CVE-2024-3116 is a critical remote code execution vulnerability in pgAdmin versions up to 8.4. The vulnerability arises from inadequate validation of file paths in the validate binary path API, specifically the /misc/validate_binary_path endpoint. Attackers can upload malicious binaries, name them to mimic legitimate PostgreSQL utilities, and trigger their execution via the API. The get_binary_path_versions() function executes the binary with the --version argument, enabling arbitrary code execution on the server, especially on Windows systems where file execution permissions are more permissive.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (modules/exploits/windows/http/pgadmin_binary_path_api.rb) that exploits a remote code execution (RCE) vulnerability (CVE-2024-3116) in pgAdmin <= 8.4 on Windows. The exploit leverages the 'validate binary path' API to upload and execute a malicious payload (typically a reverse shell or Meterpreter EXE) on the target system. The module supports both authenticated and unauthenticated exploitation, depending on the target's configuration. It interacts with several HTTP endpoints of the pgAdmin web interface to perform authentication, initialize a file manager session, upload the payload, and trigger its execution. The exploit is weaponized, as it is part of the Metasploit framework and allows for customizable payloads. The code is well-structured, with clear separation of authentication, file upload, and exploitation logic. The main entry point is the Ruby file provided, and all logic is contained within this file.
This repository contains a working exploit for CVE-2024-3116, a remote code execution vulnerability in pgAdmin <= 8.4 on Windows. The exploit consists of a Python script (exploit_cve_2024_3116.py) that automates the attack using Selenium to interact with the pgAdmin web interface. The attack flow is as follows: (1) The script logs into the target pgAdmin instance using provided credentials, (2) uploads a custom-compiled Windows executable (psql.exe) that contains a reverse shell payload, (3) configures pgAdmin to use the uploaded binary as a PostgreSQL tool, and (4) triggers execution of the binary, resulting in a reverse shell connection back to the attacker's machine. The exploit requires the attacker to have a valid user account on the target pgAdmin instance and network access to the web interface. The repository also includes a detailed README.md with setup instructions, lab environment configuration, and a step-by-step manual exploitation guide. The exploit is operational and provides a working reverse shell payload, but requires some manual steps (such as retrieving the uploaded file path via a proxy like Burp Suite).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.