CVE-2025-61301 is a denial-of-analysis vulnerability in CAPEv2 affecting reporting/mongodb.py and reporting/jsondump.py, reported against commit 52e4b43 dated 2025-05-17. An attacker with the ability to submit samples to the sandbox can craft or supply a sample whose execution produces deeply nested or excessively large behavioral data. During report generation, this data can trigger MongoDB BSON document size limits in the MongoDB reporting path or recursion/serialization failures in the orjson-based JSON dump path. As a result, CAPEv2 may fail to generate complete behavioral analysis output, leading to incomplete or missing reports for the submitted sample.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository demonstrates a denial-of-analysis exploit (CVE-2025-61301) against CAPEv2, a malware analysis sandbox. The exploit consists of a C program (onion.c) and a Python script (encrypt.py) that together generate a payload which, when executed in the sandbox, recursively spawns thousands of processes and ultimately launches a reverse shell to a specified IP and port. The recursive process forking and complex runtime behavior are designed to overwhelm CAPEv2's reporting mechanisms, specifically triggering MongoDB BSON size and nesting limits, as well as Python orjson recursion errors. This results in incomplete or missing behavioral analysis reports, allowing malicious activity to evade detection. The repository includes build instructions and a detailed README explaining the vulnerability, its impact, and how to reproduce the exploit. The main exploit capabilities are denial-of-analysis via resource exhaustion and evasion of behavioral logging, with a customizable reverse shell payload delivered via PowerShell. The code is operational and can be adapted for different recursion depths and key lengths.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.