CVE-2024-55556 affects Crater Invoice when Laravel is configured with SESSION_DRIVER=cookie. In this configuration, session state is stored client-side in the encrypted laravel_session cookie. Laravel's decryption flow unserializes decrypted data by default, so if an attacker knows the application's APP_KEY, they can decrypt, modify, and re-encrypt the session cookie with attacker-controlled serialized content. Because Crater exposes the relevant session cookie to unauthenticated users, this creates a pre-authentication exploitation path. If a suitable PHP gadget chain is present in the application's loaded dependencies, the attacker can trigger arbitrary deserialization and achieve remote command execution on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting InvoiceShelf, an open-source invoicing web application. The exploit leverages an unauthenticated PHP deserialization vulnerability (CVE-2024-55556) present when the Laravel SESSION_DRIVER is set to 'cookie' and the attacker knows or can brute-force the APP_KEY. The module allows remote code execution by crafting a malicious serialized payload, encrypting it with the APP_KEY, and injecting it into a session cookie. The exploit supports both PHP and Unix/Linux command payloads, including reverse shells and Meterpreter sessions, making it highly weaponized and flexible. The module includes checks to verify the target's vulnerability and can brute-force the APP_KEY if a list is provided. The main endpoints targeted are '/login' (for cookie manipulation and payload delivery) and '/api/v1/app/version' (for version detection). The code is written in Ruby and is structured as a standard Metasploit exploit module.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in InvoiceShelf invoicing software.
Remote code execution in Crater via Laravel session cookie deserialization when SESSION_DRIVER=cookie is enabled and the APP_KEY is known.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.