Arcane (a Docker management product) versions prior to 1.13.0 contain a command injection flaw in the updater service’s handling of lifecycle labels. The updater supports the labels com.getarcaneapp.arcane.lifecycle.pre-update and com.getarcaneapp.arcane.lifecycle.post-update to run commands before/after container updates; however, the label value is passed directly to /bin/sh -c without sanitization or validation. Because any authenticated user can create projects via the API, an attacker can create a project with a malicious lifecycle label value. When an administrator later triggers a container update (manually or via scheduled update checks), Arcane reads the label and executes the attacker-supplied value as a shell command inside the container.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
/var/run/docker.sock, or other privileged mounts that allow escaping the container boundary).If you can’t patch tonight, do this now.
/var/run/docker.sock. Consider disabling or tightly controlling automated/scheduled update checks so updates are only triggered after reviewing project configuration/labels.Patch, then assume compromise.
0.0.0-20260114065515-5a9c2f92e11f (commit 5a9c2f92e11f86f8997da8c672844468f930b7e4).6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Small standalone exploit repository containing a README and one Python PoC script. The main file, exploit_vhost.py, uses Python requests to send an HTTPS POST request to /api/mcp/connect with a crafted JSON body that places a bash command in serverConfig.command/args. The script explicitly sets the Host header to a user-supplied virtual host so the request is routed by a reverse proxy to the hidden vulnerable application. Its core capability is remote command execution leading to a bash reverse shell callback to an attacker-controlled listener. The exploit disables TLS verification, expects a read timeout as a success indicator, and is intended for direct command-line use with five arguments: target host, target port, virtual host, listener host, and listener port. The repository is a real exploit PoC rather than a detector, with an operational but basic hardcoded payload and no broader framework integration.
This repository is a small standalone Python exploit PoC for CVE-2026-23520. It contains two files: a README describing the vulnerability and usage, and a single executable script, exploit_vhost.py. The script uses Python requests to send an HTTPS POST request to /api/mcp/connect with a crafted JSON body containing serverConfig.command and serverConfig.args values intended to trigger command injection. Its distinguishing feature is explicit support for virtual-host-based routing by setting a user-supplied Host header, allowing the exploit to reach a backend service hidden behind a reverse proxy. The payload is a hardcoded bash reverse shell using /dev/tcp/{lhost}/{lport}. The script disables TLS verification warnings, accepts target host/port, virtual host, and callback host/port as command-line arguments, and treats a read timeout as a likely indicator of successful exploitation because the shell may hold the HTTP transaction open. This is a real exploit PoC rather than a detector, with operational but basic payloading and no framework integration.
This repository is primarily a collection of HackTheBox writeups, but it also contains real exploit automation in the `VariaType/` directory. The actionable exploit consists of one Bash orchestrator (`exploit_variatype.sh`) and four Python phase scripts. The exploit is not tied to a common framework like Metasploit; it is custom automation for a multi-stage Linux target compromise. Main exploit capabilities: (1) reconnaissance and extraction of credentials from an exposed `.git` repository on `portal.variatype.htb`; (2) login and LFI verification against `download.php`; (3) preparation of malicious font files and a crafted designspace document to exploit CVE-2025-66034 in fontTools varLib, causing arbitrary file write of a PHP webshell to `/var/www/portal.variatype.htb/public/files/shell.php`; (4) privilege escalation to user `steve` using a ZIP filename command injection payload associated with CVE-2024-25082, which appends an attacker SSH key into `/home/steve/.ssh/authorized_keys`; and (5) privilege escalation to root by abusing `sudo /usr/bin/python3 /opt/font-tools/install_validator.py` with a URL-encoded absolute path traversal to write the attacker’s public key into `/root/.ssh/authorized_keys`. Repository structure: most files are Markdown writeups for HTB machines/challenges. Only 5 files contain exploit code, all under `VariaType/`. `phase1_git_extract.py` handles exposed Git extraction and credential recovery. `phase2_rce_exploit.py` generates malicious font/designspace artifacts for the webshell stage, though upload is partly left manual in that script. `phase3_privesc_steve.py` generates an SSH key, builds an evil ZIP with a filename-based command injection payload, serves it over HTTP, and attempts to place it on the target for later processing. `phase4_privesc_root.py` serves a root public key and invokes the vulnerable validator script over SSH as steve to gain root SSH access. `exploit_variatype.sh` ties the phases together into a mostly automated end-to-end attack. Overall, this is a valid exploit repository with operational code, not just detection logic. The exploit targets a web-exposed Linux application stack and culminates in full root compromise with SSH persistence.
This repository is a small standalone Python PoC for CVE-2026-23520, described as an MCP API remote command execution issue. The repository contains only two files: a README with usage guidance and exploit.py, the sole executable entry point. The exploit accepts a target host/domain/full URL plus attacker callback parameters, builds a URL using a configurable scheme, port, and endpoint, and sends a POST request with a crafted JSON body to the MCP API endpoint. The malicious request places attacker-controlled command execution data in serverConfig.command and serverConfig.args, specifically invoking bash with a reverse shell one-liner. If the target is vulnerable, it connects back to the supplied lhost:lport and provides an interactive shell. The code is operational rather than a mere detector: it includes a working payload, disables TLS verification warnings, supports verbose debugging, and treats read timeouts as potentially successful exploitation. No framework affiliation is present, and there are no additional modules, staging logic, persistence features, or evasion capabilities beyond the basic reverse shell delivery.
This repository is a minimal proof-of-concept exploit for CVE-2026-23520 affecting Arcane MCP. It contains only two files: a short README and a single Python script, cve-2026-23520.py, which is the main exploit entry point. The script uses the requests library and command-line arguments for target host, target port, callback host, and callback port. The exploit constructs an HTTPS POST request to /api/mcp/connect on the target. It sends JSON data with a serverConfig object that specifies command="bash" and args=["-c", <payload>], where the payload is a bash reverse shell. The reverse shell uses /dev/tcp/<lhost>/<lport> to connect back to the attacker. TLS certificate verification is explicitly disabled with verify=False, and the request timeout is set to 5 seconds. Operationally, the exploit's capability is straightforward: unauthenticated remote command execution leading to a reverse shell if the endpoint accepts the supplied configuration and the target can reach the attacker over the network. There is no vulnerability check, target fingerprinting, authentication handling, payload staging, or post-exploitation logic. The README confirms the intended target and usage, though it references exploit.py while the actual script filename is cve-2026-23520.py. Overall, this is a small, direct operational PoC rather than a framework module or detection script.
This repository is a small standalone Python proof-of-concept for CVE-2026-23520 affecting Arcane Docker Management versions earlier than 1.13.0. The repo contains only two files: a README describing the vulnerability, attack flow, usage, and endpoint strategy; and a single executable script, poc.py, which implements the exploit logic using only Python standard library modules such as argparse, urllib, json, ssl, and re. The exploit is not part of a larger framework. Its main capabilities are: (1) fingerprinting a target Arcane instance by probing multiple possible version endpoints and parsing flexible version keys; (2) authenticating with a valid low-privileged Arcane account and extracting a token from several possible response key names; (3) enumerating Arcane environments/endpoints; (4) creating a malicious project or compose deployment through several possible API routes; and (5) generating an offline poisoned compose file without network access. The script supports three modes: check, exploit, and generate. The core exploit technique is authenticated API abuse to plant a docker-compose definition containing one of Arcane's lifecycle labels, either com.getarcaneapp.arcane.lifecycle.pre-update or com.getarcaneapp.arcane.lifecycle.post-update, with an attacker-controlled shell command as the label value. According to the repository, Arcane passes that value directly to /bin/sh -c during update processing. The exploit itself does not directly trigger code execution; instead, it stages the malicious project and relies on a later administrator-initiated container update to execute the payload. The default payload is the benign command 'id', but the user can supply arbitrary shell commands. Repository structure is straightforward: README.md serves as documentation and operational guidance, while poc.py is the sole code file and likely entry point due to its shebang and __main__ block. The code appears operational rather than merely demonstrative because it includes resilient endpoint probing, authentication handling, environment discovery, project deployment logic, CLI parsing, and TLS options. It is therefore best classified as an operational PoC with a hardcoded but user-supplied shell-command payload model.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.