Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains two Markdown documentation files and one standalone Python exploit, poc/exploit.py. The Python script embeds a PHP webshell and implements the complete attack chain using requests.Session: retrieve a CSRF token, log in, initialize an upload with a malicious filename, upload one chunk, finalize the write, and invoke the resulting shell. There is no exploit-framework integration. The vulnerability is an unchecked filename in the resumable upload workflow. According to the supplied documentation, uploadInit stores fileName without path sanitization, and uploadFinalize validates destination directories but not the final path passed to fopen(). Supplying ../../app/poc_rce.php therefore escapes the permitted storage folder. A writable, PHP-executing web root turns the arbitrary file write into remote command execution. The script uses overwrite policy, potentially replacing an existing file at the selected destination. The payload and traversal are hardcoded, while the target URL, credentials, and allowed folder are command-line arguments. This is an operational exploit rather than a detection script, but success was not independently verified. Error handling is limited: the script checks for a missing uploadId but does not rigorously validate login, chunk upload, finalization, or command execution. It does not remove the planted webshell. The README identifies CVE-2026-104826 and GHSA-7626-89vx-5rpc, reports testing v1.1 at target-project commit 68858e0, and states that v1.2 fixes the issue. These claims are based on the supplied material. No analyzed repository URL, repository reference, or archive size was provided; the repository metadata fields use empty strings and zero for unknown values. The three listed file sizes total 9,054 bytes, which is not a known archive size.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.