PyMySQL through version 1.1.0 is vulnerable to SQL injection when untrusted JSON input is used, due to the escape_dict function not escaping keys. This allows an attacker to inject arbitrary SQL if user-controlled JSON keys are incorporated into SQL queries without proper sanitization.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained proof-of-concept lab for CVE-2024-36039, demonstrating how PyMySQL <= 1.1.0 can turn object injection into SQL injection when dictionary keys are custom objects. The main exploit logic is in app.py, a small Flask service exposing POST /search. It accepts JSON, converts each JSON key into a CustomKey object, and passes the resulting dictionary as a bound parameter to PyMySQL. Because CustomKey.__str__/__repr__ returns attacker-controlled text and vulnerable PyMySQL versions fail to properly quote object-based dictionary keys, the serialized dictionary is embedded into SQL in an unsafe form. The exploit chain relies on MariaDB's ODBC escape syntax. A crafted JSON key such as fn/* and a value such as */ 1} UNION SELECT 1, flag, 3 FROM secret -- cause the malformed dictionary representation to be parsed as a valid ODBC expression followed by injected SQL. The provided payload performs a UNION SELECT against the secret table and returns the seeded flag. This is an actual exploit PoC rather than a detector: it stands up a vulnerable environment and demonstrates successful data extraction. Repository structure is minimal and purpose-built: app.py contains the vulnerable web app; init.sql creates the iot_logs database, logs table, and secret table with a sample flag; requirements.txt pins Flask 3.0.0 and vulnerable PyMySQL 1.1.0; Dockerfile packages the app and exposes port 9669; docker-compose.yml orchestrates the Flask service and a MariaDB 10.11 backend, mapping port 9669 and mounting the initialization SQL. README.md provides a detailed explanation of the vulnerability, exploitation steps, curl examples, and remediation guidance to upgrade to PyMySQL 1.1.1 or later.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.