The Meta-box GalleryMeta plugin for WordPress is vulnerable to stored cross-site scripting (XSS) via its admin settings in all versions up to and including 3.0.1. The issue is caused by insufficient input sanitization and output escaping of settings values, allowing an authenticated attacker with editor-level permissions or higher to store arbitrary script payloads that execute in victims’ browsers when they access affected pages. The vulnerability is reported to affect only WordPress multisite installations and installations where the unfiltered_html capability has been disabled.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit project for Langflow path traversal, consisting of a license, a README, and a single executable script: langflow_exploit.py. The script is the clear entry point and implements an interactive network exploit workflow against a user-supplied Langflow base URL. Core capability: the exploit targets CVE-2026-1302 / GHSA-vwmf-pq79-vjvx and uses HTTP requests to the target's /files/ path with ../../../../../../ traversal sequences to read arbitrary files from the server. It first checks reachability, then queries /api/v1/version to identify the Langflow version, and finally tests exploitation by requesting /files/../../../../../../etc/passwd. If successful, it enters an interactive loop allowing the operator to request additional file paths for disclosure. Secondary capability: the script includes an RCE attempt, but it is much less substantiated than the file-read path. It builds a Python reverse shell payload and tries to POST it to /api/v1/components as a malicious component, then trigger execution via /api/v1/components/malicious_component/execute. If that fails, it attempts to POST the payload directly to /files/../../../../../../tmp/langflow_revshell.py. This logic is speculative and depends on target-side behavior not validated by the script, so the repository should primarily be understood as an arbitrary file-read exploit with an opportunistic reverse-shell module. Repository structure is minimal and purpose-built: README.md documents installation, interactive usage, example target URLs, example sensitive files such as /app/langflow/.env, and the optional reverse shell workflow; langflow_exploit.py contains all exploit logic. No framework affiliation is present, no modularization exists beyond helper functions, and the code uses the Python requests library for all network interaction. Overall, this is a real exploit PoC/operational script for remote file disclosure against vulnerable Langflow instances, with an additional but unreliable code-execution attempt layered on top.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.