Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small proof-of-concept for CVE-2026-21001, demonstrating an out-of-bounds read in a WebAssembly module caused by unsafe Rust pointer arithmetic without bounds checking. The repository contains four files: a LICENSE, a README with build/run instructions, a Python exploit harness (exploit_wasm_oob.py), and the vulnerable Rust source (wasm_vuln.rs). The Rust code exports get_value(index: i32), creates a fixed array [10, 20, 30, 40], and unsafely dereferences array.as_ptr().offset(index as isize), allowing attacker-controlled indexing beyond the array boundary. The Python script loads the compiled wasm_vuln.wasm using Wasmer, resolves the exported get_value function, and calls it with index 100 to demonstrate memory disclosure. There are no network callbacks, C2 endpoints, or remote delivery mechanisms in the code; exploitation is local to the runtime hosting the WASM module, though the vulnerability class is relevant to browser and web-embedded WASM contexts as well. The exploit capability shown is limited to a basic out-of-bounds read demonstration rather than a full RCE chain, so the repository is best classified as a POC rather than an operational or weaponized exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.