CVE-2024-9264 is a critical code-injection vulnerability in Grafana 11 SQL Expressions, an experimental feature. User-influenced SQL expressions are insufficiently sanitized before evaluation by DuckDB. Crafted expressions can abuse DuckDB functionality to inject operating-system commands and access local files.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
11 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is a small standalone Python exploit PoC for CVE-2024-9264 affecting Grafana SQL Expressions when DuckDB is available. The repo contains one main exploit script (CVE-2024-9264.py), a README with usage and affected-version details, a requirements file, and placeholder image directory content. The exploit is not part of a larger framework. The script authenticates to Grafana using supplied or default Basic Auth credentials and sends crafted requests to the SQL Expressions datasource API endpoint /api/ds/query?ds_type=__expr__&expression=true&requestId=Q100. It supports two primary exploit capabilities: arbitrary local file read using DuckDB read_blob(), and command execution by installing/loading the DuckDB shellfs extension and abusing a pipe-backed read_csv() call to execute a base64-decoded bash command. Command output is redirected to /tmp/cve_2024_9264_out and then read back through another read_blob() query. A reverse-shell mode constructs a bash /dev/tcp callback using attacker-provided lhost/lport. Operationally, the script includes CLI parsing, target normalization, dry-run mode, optional debug output, TLS verification toggles, and a validation workflow that typically performs a file-read proof (default /etc/passwd) before command execution. The README states exploitation requires valid Grafana credentials and Viewer-or-higher access, and that command execution depends on DuckDB being present in the Grafana process PATH; standard Grafana installs do not include DuckDB by default. Overall, this is a real authenticated web exploit with practical LFI and conditional RCE capability, suitable as an operational PoC rather than a mere detector.
This repository is a small standalone proof-of-concept for CVE-2024-9264 affecting Grafana SQL Expressions. The main exploit logic is in PoC.py, a Python script that authenticates to a target Grafana instance and POSTs crafted JSON to /api/ds/query with datasource type/uid set to __expr__ and query type sql. The operator can either supply a file path with -f, which is converted into a DuckDB query using read_csv_auto('<path>') for local file inclusion, or provide arbitrary SQL directly with --cmd. The script then parses the JSON response and prints extracted rows, making it operational for data exfiltration rather than mere detection. Repository structure is minimal: PoC.py contains the exploit, README.md documents the vulnerability, setup, and usage in Korean, and docker-compose.yml provides a lab environment exposing Grafana 11.0.0 on port 3000 via the vulhub/grafana:11.0.0 image. The README states the attack requires authenticated access, typically admin/admin in the demo environment, and highlights LFI and possible RCE through DuckDB SQL execution. No advanced payload staging, persistence, or framework integration is present; this is a direct authenticated web exploit PoC with a basic but functional SQL payload path.
This repository is a self-contained lab for demonstrating exploitation of CVE-2024-9264, a Local File Inclusion (LFI) vulnerability in Grafana 11.x when using SQL Expressions with DuckDB. The repository includes a Dockerfile that builds a vulnerable Grafana 11.1.5 instance with DuckDB installed, and sets up a known flag file at /opt/flag.txt. The main exploit is implemented in 'exploit.sh', a Bash script that logs in to the Grafana instance (default admin/admin), crafts a SQL Expression payload using DuckDB's read_text() function to read arbitrary files, and sends it to the /api/ds/query endpoint. If successful, the script extracts and prints the flag from the server's response. The repository also includes configuration files (grafana.ini), a sample cookies.txt, and an entrypoint script for Docker. The exploit demonstrates post-auth LFI via network requests to the Grafana API, and is intended for educational use in a controlled environment.
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-9264, a critical authenticated remote code execution (RCE) vulnerability in Grafana v11.0. The exploit leverages the experimental 'SQL Expressions' feature, which passes user-supplied SQL directly to the DuckDB CLI without proper sanitization. The exploit is implemented as a Bash script ('exploit.sh') that automates the attack: it logs into the target Grafana instance using provided credentials, sends a malicious SQL payload to write a reverse shell command to a temporary file, and then triggers execution of that command via the SQL Expressions API. The attacker must provide the target Grafana URL, valid credentials, and their own IP and port for the reverse shell. The exploit requires the 'duckdb' binary to be present in the server's PATH. The repository also includes a README.md with usage instructions and background information. No detection or fake code is present; this is a functional PoC exploit.
This repository contains a Python exploit script (CVE-2024-9264.py) targeting Grafana instances vulnerable to CVE-2024-9264. The exploit works by first authenticating to the target Grafana server using provided credentials. It then leverages the Expression data source to execute arbitrary shell commands on the server by crafting a malicious SQL-like query. The output of the command is redirected to a temporary file (/tmp/output.txt), which is then retrieved using a local file inclusion (LFI) technique via another crafted query. The script is operational and provides full remote code execution (RCE) capabilities, requiring only network access to the target and valid user credentials. The repository also includes a minimal README.md with usage instructions. No framework is used; the exploit is standalone and written in Python.
This repository contains a Python proof-of-concept exploit for CVE-2024-9264, a remote code execution vulnerability in Grafana (version 11.x.y and above) via SQL Expressions. The exploit requires valid Grafana credentials (Viewer or higher) and the presence of the DuckDB binary. The main script, poc.py, authenticates to the target Grafana instance, crafts a malicious SQL expression that writes a reverse shell command to /tmp/rev, and then triggers its execution using the shellfs community extension. The exploit leverages the /login and /api/ds/query endpoints to perform authentication and payload delivery. If successful, it establishes a reverse shell from the Grafana server to an attacker-controlled host. The repository is structured with a single exploit script and a README providing usage instructions and background information.
This repository contains a fixed and functional proof-of-concept exploit for CVE-2024-9264, a critical remote code execution vulnerability in Grafana (tested on version 11.0.0). The exploit leverages the DuckDB backend and the 'shellfs' extension to write and execute a reverse shell script on the target server. The main exploit script (fpoc.py) authenticates to the Grafana instance using provided credentials, writes a bash reverse shell script to /tmp/rev.sh via a crafted SQL expression, and then executes it to establish a reverse shell connection to the attacker's machine. The README provides detailed usage instructions and requirements. The exploit targets network-exposed Grafana instances with specific backend and extension capabilities, and requires valid credentials. The repository is structured with a single Python exploit script and a README file.
This repository is a Go-based exploit tool targeting CVE-2024-9264, a critical SQL injection vulnerability in Grafana that allows authenticated attackers to achieve remote code execution (RCE) and arbitrary file read. The repository contains three files: a README.md with detailed usage instructions and vulnerability background, a go.mod for Go module management, and the main exploit code in main.go. The exploit operates by authenticating to a vulnerable Grafana instance using provided credentials, then abusing the /api/ds/query endpoint to inject malicious SQL expressions. These expressions can: - Read arbitrary files from the server (e.g., /etc/passwd) - Execute arbitrary shell commands (e.g., 'ls -al') - Deploy a reverse shell payload, connecting back to an attacker-controlled IP and port The tool is command-line driven, supporting flags for the attack type, target URL, credentials, and payload parameters. It requires the attacker to have valid Grafana credentials and network access to the target. The code is operational, providing real exploitation capabilities rather than just detection or proof-of-concept. Key endpoints include the Grafana login and query API, and the exploit leverages temporary files on the target for command output and reverse shell payloads.
This repository provides a Python proof-of-concept exploit for CVE-2024-9264, a post-authentication DuckDB SQL injection vulnerability in Grafana's experimental SQL Expressions feature. The exploit allows an authenticated user to execute arbitrary DuckDB SQL queries, enabling file read on all vulnerable versions and remote command execution on version 11.0.0. The main script, CVE-2024-9264.py, uses the 'ten' Python framework for argument parsing and session management. It authenticates to the target Grafana instance via the /login endpoint, then sends crafted requests to /api/ds/query to perform SQL injection. The exploit can read arbitrary files using the DuckDB read_blob function, or (on v11.0.0) execute shell commands by installing and loading the shellfs extension and reading command output from a temporary file. The README provides detailed usage instructions, affected versions, and mitigation advice. The exploit requires the DuckDB binary to be installed and present in the system PATH on the target server, which is not the default for Grafana installations. The repository is well-structured, with a single main exploit script, a requirements.txt for dependencies, and comprehensive documentation.
This repository provides a working proof-of-concept exploit for CVE-2024-9264, a critical remote code execution vulnerability in Grafana 11.x.y. The exploit is implemented in a single Python script (poc.py) that authenticates to a target Grafana instance using provided credentials, abuses the SQL Expressions feature (with the DuckDB backend and the shellfs extension) to write a reverse shell script to /tmp/rev, and then triggers its execution. The exploit requires the attacker to have at least 'Viewer' access to the Grafana instance and for DuckDB to be installed and accessible. The Dockerfile and docker-compose.yml files are provided to help set up a vulnerable Grafana environment for testing. The main attack vector is network-based, targeting the Grafana web API endpoints. The exploit results in a reverse shell connection from the server to an attacker-controlled host, granting remote command execution capabilities.
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-9264, a critical file read vulnerability in Grafana version 11.x.y (>=11.0.0) when DuckDB is installed and accessible. The main exploit is implemented in 'poc.py', a Python script that authenticates to a target Grafana instance using provided credentials, then abuses the SQL expression query feature to execute a DuckDB query that reads arbitrary files from the server filesystem. The script sends requests to the '/login' and '/api/ds/query' endpoints, leveraging DuckDB's 'read_csv_auto' function to access files such as '/etc/passwd'. The repository also includes a Dockerfile and docker-compose.yml for setting up a vulnerable Grafana environment with DuckDB and MySQL, and a README.md with usage instructions and references. The exploit requires an authenticated user (Viewer or higher) and is intended for educational or authorized testing purposes only.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A command-injection/remote-code-execution vulnerability in Grafana SQL Expressions involving DuckDB read_blob SQL expressions. The referenced material demonstrates exploitation against Grafana 11.0.0 and adds a Metasploit exploit module.
Critical command injection vulnerability in Grafana v11 related to insufficient sanitization of user-controlled input passed to the experimental DuckDB query feature, enabling command injection (and local file inclusion) that can lead to remote code execution under certain conditions.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.