CVE-2025-53691 is a deserialization of untrusted data vulnerability in Sitecore Experience Manager (XM) and Sitecore Experience Platform (XP) that allows remote code execution. The provided content identifies the vulnerable behavior as insecure .NET BinaryFormatter deserialization in Sitecore.Convert.Base64ToObject, which deserializes attacker-controlled base64 data without a restrictive binder or equivalent validation. According to the supplied research context, this deserialization sink is reachable through the convertToRuntimeHtml pipeline, specifically when attacker-controlled HTML is processed by Sitecore.Pipelines.ConvertToRuntimeHtml.ConvertWebControls. The write-up further states that Sitecore.Shell.Applications.ContentEditor.Dialogs.FixHtml.FixHtmlPage can be used to pass attacker-supplied HTML into RuntimeHtml.Convert and then CorePipeline.Run("convertToRuntimeHtml"), ultimately triggering deserialization and code execution. The issue affects Sitecore XM and XP versions 9.0 through 9.3 and 10.0 through 10.4.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a comprehensive proof-of-concept exploit chain targeting three critical vulnerabilities in Sitecore Experience Platform (XP) up to version 10.4.1: CVE-2025-53694 (information disclosure), CVE-2025-53693 (cache poisoning), and CVE-2025-53691 (remote code execution via deserialization). The main exploit logic resides in 'chain.py', a Python script that automates the full attack sequence: it first leverages the ItemService API to enumerate internal Sitecore data, then abuses the XAML handler to poison the application cache, and finally exploits insecure deserialization in the AjaxScriptManager to achieve unauthenticated RCE. The repository also includes a Nuclei detection template ('sitecore.yaml') for automated vulnerability scanning, a detailed technical report ('REPORT.md'), and search dorks ('dorks.md') for identifying potential targets. The exploit is operational, requiring only a target URL and a command to execute. The attack is performed entirely over HTTP(S) endpoints exposed by vulnerable Sitecore instances, with no authentication required. The code is well-structured, modular, and provides clear output for each attack stage. This repository is a high-quality resource for both offensive security research and defensive mitigation planning.
This repository contains a Python exploit script (exploit.py) targeting CVE-2025-53691, a remote code execution vulnerability in Sitecore Experience Platform due to insecure deserialization in the AjaxScriptManager. The exploit works by sending a malicious serialized .NET payload (generated via ysoserial.net or a manual template) to the /-/xaml/{control_path} endpoint, invoking methods such as ProcessSerializedData to trigger deserialization and execute arbitrary commands on the server. The script supports command-line arguments for the target URL, command to execute, timeout, SSL verification, and output file. The README provides a technical overview and mitigation advice. The LICENSE is MIT. The exploit is operational, requiring a vulnerable, unpatched Sitecore instance with accessible XAML endpoints. The main attack vector is network-based, exploiting HTTP POST requests to the Sitecore XAML endpoints.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Sitecore Experience Platform insecure deserialization vulnerability that can lead to remote code execution.
A recent Sitecore vulnerability mentioned only as part of a possible exploit chain with CVE-2025-53690; no further technical detail is provided in the content.
An additional 2025 Sitecore vulnerability mentioned in a list of recent critical issues, without further detail in the content.
A post-auth remote code execution vulnerability in Sitecore Experience Platform reachable via the convertToRuntimeHtml pipeline, where attacker-controlled HTML can trigger an unsafe BinaryFormatter deserialization sink (Sitecore.Convert.Base64ToObject), enabling code execution with a suitable gadget chain.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.