CVE-2025-32778 is an unauthenticated command injection vulnerability in the Web-Check OSINT application (Lissy93/web-check) affecting versions prior to 2.0.1. The flaw is present in the /api/screenshot endpoint, where attacker-controlled input supplied via the url parameter is passed unsafely into a shell command through exec(). Because the input is not properly sanitized or isolated from the shell, an attacker can inject arbitrary shell metacharacters and execute system commands on the host running Web-Check. The issue was reportedly fixed by replacing exec() with execFile(), eliminating shell interpretation of user input.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python proof-of-concept exploit for CVE-2025-32778, a critical command injection vulnerability in the Web-Check OSINT tool by Lissy93. The exploit targets the '/api/screenshot/' HTTP endpoint, which is vulnerable to unauthenticated command injection via the 'url' parameter. The main script, 'cve-2025-32778.py', allows an attacker to specify a target URL and either provide a custom shell command or generate a reverse shell payload (using netcat) to gain remote code execution on the target server. The script normalizes the target URL, encodes the payload for safe injection, and sends a crafted HTTP GET request to trigger the vulnerability. The exploit is operational and can be used to obtain a shell on the target system, provided the attacker has network access to the vulnerable endpoint. The repository is structured with standard documentation and security policy files, and the exploit code is self-contained in a single Python script.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated command injection vulnerability in Web-Check.
A critical command injection vulnerability in Web-Check versions earlier than 2.0.1 via the /api/screenshot endpoint.
A remote code execution vulnerability in the Web-Check screenshot API, referenced as a Metasploit module PR.
A command injection vulnerability referenced for inclusion as a Nuclei detection template.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.