CVE-2026-1337 affects Neo4j Enterprise and Community editions prior to version 2026.01. The issue is caused by insufficient escaping of unicode characters in the query log output. An attacker who can cause crafted content to be written into Neo4j query logs may be able to inject data that becomes executable script when those logs are later opened in a viewer or tool that interprets the log contents as HTML rather than plain text. Based on the provided advisory, the issue is limited to downstream log handling and viewing; there is no stated direct security impact on Neo4j product runtime itself.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small proof-of-concept exploit/demo for CVE-2026-1337, a simulated prompt-injection-to-command-injection vulnerability in an AI-assisted code review bot. The repo contains two Python programs: ai_code_review_bot.py, which implements the vulnerable Flask service, and exploit.py, which sends a malicious comment to trigger code execution. README.md documents the scenario and usage; LICENSE is standard MIT. The vulnerable service exposes a POST /webhook endpoint. It extracts a JSON 'comment' field, passes it to ai_fix_suggestion(), and if the text contains '##Fix:' it blindly returns everything after that marker as the shell script to run. sanitize_code() then applies only a naive substring blacklist for rm, shutdown, curl, wget, and /bin/bash. The resulting script is written to a temporary .sh file, marked executable, and run via subprocess.run(['/bin/bash', temp_file], ...). This creates a direct path from attacker-controlled input to shell execution. The exploit script uses requests to POST to http://127.0.0.1:5000/webhook. It includes two bypass concepts: one reconstructs 'curl' using shell variable expansion (cur\${empty}l), and the active payload uses base64 encoding to hide the forbidden command from the blacklist. The chosen payload decodes to a curl command that contacts an attacker-controlled URL and includes whoami output, demonstrating both arbitrary command execution and simple exfiltration/callback behavior. Overall, this is a functional exploit demonstration rather than a detection script. It is not part of a known exploitation framework. The code is operational but basic: the payload is hardcoded, the target is fixed to localhost:5000, and the scenario is explicitly educational/simulated.
Repository contains a single Python proof-of-concept demonstrating CVE-2026-1337: authenticated log injection in Neo4j query logging when logs are in plain-text (non-JSON) format. Structure: (1) README.md explains the issue, shows example payload/log output, and provides a run command; (2) log_injection_poc.py is the executable PoC. Core behavior: the script connects to a Neo4j instance over the Bolt protocol using neo4j.GraphDatabase.driver() with user-supplied --uri/--user/--password. It first runs a legitimate Cypher query (MATCH (n:RealQuery) RETURN n LIMIT 1) to create baseline log entries. It then begins a new transaction with crafted transaction metadata (metadata={"x": payload}) where payload starts with a quote-closure and newline ("'\n") and then includes multiple attacker-generated lines that mimic Neo4j’s query.log format (both “Query started” and completion lines). Because control characters/newlines are not escaped in the logged metadata field, the injected lines appear as separate, legitimate log entries, allowing log forgery (e.g., fake queries, fake users, fake client IPs). Capabilities/impact: does not execute arbitrary code or run the forged queries; it forges audit trails by injecting believable log lines. README notes potential secondary risks if the same unescaped content is consumed by log viewers (e.g., XSS in web-based log analysis tools or ANSI escape injection in terminal viewers).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.