CVE-2024-55963 is an improper access control vulnerability in Appsmith before version 1.51. A user account that does not have administrative privileges can invoke the Appsmith restart API and cause the Appsmith server process to restart. The issue stems from incorrect authorization checks on the API endpoint: the request should require super user permissions, but those checks are not properly enforced. The restart occurs within the Appsmith container and affects the Appsmith service itself rather than enabling escape from the container or direct compromise of the host.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python exploit script (CVE‑2024‑55963.py) and a detailed README for CVE-2024-55963, a remote code execution (RCE) vulnerability in Appsmith (v1.20–v1.51). The exploit automates the process of registering or logging in to a vulnerable Appsmith instance, creating a workspace and application, and setting up a PostgreSQL datasource pointing to localhost with default credentials. It then uploads a custom PL/pgSQL function (exec_cmd) that leverages PostgreSQL's COPY PROGRAM feature to execute arbitrary system commands or spawn a reverse shell. The script supports both modern and legacy Appsmith server versions by detecting the presence of the environmentId feature. The README provides usage instructions, version compatibility, and a technical overview. The main exploit file is self-contained, requires only Python 3.8+ and the requests library, and is operational for red-team or testing purposes. The attack vector is network-based, targeting the Appsmith web API endpoints, and the exploit provides full command execution or reverse shell access on the target server.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.