In Webhood versions 0.9.0 and earlier, the backend container images are vulnerable due to missing authentication on the Pocketbase admin API endpoint responsible for admin account creation. If no admin account exists (the default state after deployment), an unauthenticated attacker can send a crafted HTTP request to the /api/admins endpoint and create a new admin account, gaining full administrative access to the backend database.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
/api/admins endpoint, for example via firewall rules or reverse proxy configuration, to prevent unauthenticated access until the software can be upgraded.Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This eight-file repository is a Docker-based local reproduction lab for CVE-2024-31218, a Webhood authentication-control failure affecting versions through 0.9.0. The primary exploit, exploit/reproduce.py, is a standalone Python script using urllib that POSTs a hardcoded JSON account payload to ${LAB_URL:-http://127.0.0.1:8090}/api/admins without an authorization token. Acceptance (HTTP 200/201) indicates that it created the supplied synthetic administrator account, enabling administrative access. detection/detect.py performs the same state-changing probe with separate synthetic credentials and reports whether unauthenticated creation was accepted or blocked. The vulnerable Docker configuration downloads PocketBase 0.22.10 and exposes it only as 127.0.0.1:8090; a second compose file maps a remediation test service to 127.0.0.1:8091. README and evidence documents explain that the Docker lab models the underlying PocketBase API behavior rather than packaging the complete vulnerable Webhood application, and describe Webhood 0.9.1 as the fixed release. No exploit framework is used; the payload is hardcoded but the LAB_URL environment variable makes the destination configurable.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.