CVE-2024-56331 affects Uptime Kuma, an open-source self-hosted monitoring tool. The vulnerability is an improper URL handling issue in the Real-Browser monitor/request type. User-supplied URL input is not adequately validated server-side, allowing an authenticated user to provide a file:// URI such as file:///etc/passwd despite the client-side pattern intending to restrict input to HTTP(S). The backend passes the attacker-controlled URL to a browser instance used to render the target and capture a screenshot. When a local file URI is supplied, the browser loads local server files and the application captures their contents in the resulting screenshot. This enables local file disclosure from the host running Uptime Kuma, including potentially sensitive operating system and application files such as /etc/passwd, /etc/shadow, kuma.db, or config.json. The issue is fixed in version 1.23.16.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains an exploit for CVE-2024-56331, a Local File Inclusion (LFI) vulnerability in Uptime Kuma's 'real-browser' monitor feature. The exploit leverages improper URL handling, allowing an authenticated attacker to supply file:// URLs and cause the server to take screenshots of local files, effectively exfiltrating their contents. The repository consists of two files: a detailed README.md explaining the vulnerability, impact, and exploitation steps, and exploit.js, a Node.js script that automates the attack. The script connects to the Uptime Kuma server via WebSocket, authenticates with provided credentials, and submits requests for a list of sensitive files, exploiting the LFI to retrieve their contents. The exploit targets Linux systems and specifically attempts to access system files and Uptime Kuma's own database and configuration files. The attack vector is network-based, requiring access to the Uptime Kuma WebSocket API as an authenticated user.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.