A vulnerability in Olivetin version 2025.4.22 allows OS command injection via the ParseRequestURI function in service/internal/executor/arguments.go when handling custom themes. Unsanitized input passed to this function can be used to execute arbitrary operating system commands.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, single-purpose Python exploit for CVE-2025-50946 affecting OliveTin's get-theme functionality. The repo contains only three files: a standard Python .gitignore, a README with usage examples, and one executable Python script (cve-2025-50946.py). There is no framework integration, no auxiliary modules, and no detection-only logic. The exploit flow is straightforward: it validates that the supplied target is a bare HTTP/HTTPS URL containing only an IP address, derives the final target by appending a user-supplied or default port, and sends a POST request to /api/StartAction. The JSON body uses a hardcoded actionId (8efb249e-b0a3-4842-9f67-e04b67b7a750) corresponding to OliveTin's Get Theme action and injects a shell command into the themeGitRepo argument by setting it to http://t;<payload>. To work around character restrictions, the script replaces spaces in the supplied command with $IFS. After triggering execution, it sends a GET request to /api/GetLogs with a Referer header pointing to /logs, filters returned log entries by the same actionId, extracts the latest output, removes blank lines and the expected 'olivetin-get-theme: not found' noise, and prints the resulting command output. Main capability: remote arbitrary command execution against a vulnerable OliveTin instance, with output retrieval via the application's logging API. The exploit is operational rather than a bare PoC because it automates both command delivery and output collection, but payload customization is limited to a single injected shell command string. The README examples demonstrate commands such as 'id' and 'ps -efH', and the sample output indicates execution as root on a Linux host.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.