CVE-2024-48914 affects Vendure, an open-source headless commerce platform. In versions prior to 3.0.5 and 2.3.3, the @vendure/asset-server-plugin, when used with LocalAssetStorageStrategy, improperly handles asset request paths, allowing a crafted request to traverse directories outside the intended asset root and read arbitrary files from the server filesystem. This can expose sensitive local files such as configuration files, environment files, credentials, and other application or system data. The same request-handling code path also contains a malformed URI handling issue that can cause the server to crash, resulting in denial of service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-48914, a vulnerability in Vendure's asset server plugin (prior to versions 3.0.5 and 2.3.3). The exploit is implemented in Python (CVE-2024-48914.py) and allows an attacker to perform two main actions: (1) read arbitrary files from the server's filesystem via a path traversal attack by sending a crafted HTTP GET request to the /assets endpoint, and (2) crash the server by sending a malformed URI to the same endpoint. The exploit uses prepared requests to bypass path normalization that would otherwise strip '../' sequences. The repository includes a README with detailed usage instructions, setup guidance for a vulnerable Vendure environment, and analysis of the root cause in the Vendure source code. No hardcoded endpoints or credentials are present; the user must supply the target URL and desired file. The exploit is a functional PoC and not weaponized, requiring manual input for each attack.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.