manga-image-translator (zyddnys/manga-image-translator) beta-0.3 and earlier, when run in shared API mode, exposes FastAPI POST endpoints /simple_execute/{method} and /execute/{method} that deserialize attacker-controlled HTTP request bodies using Python pickle.loads() without validation. Although a nonce-based authorization check (X-Nonce) is intended to gate access, the nonce defaults to an empty string (via MT_WEB_NONCE defaulting to ''), making the guard condition falsy and causing the authorization check to be skipped in default deployments. An unauthenticated remote attacker can send a crafted pickle payload (e.g., leveraging reduce) to trigger arbitrary code execution during deserialization in the server process context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unsafe Python pickle deserialization issue in manga-image-translator (shared API mode) enabling unauthenticated remote code execution via FastAPI endpoints that call pickle.loads() on attacker-controlled data, compounded by a default-empty nonce that bypasses intended authorization.
Unauthenticated remote code execution in zyddnys/manga-image-translator shared-mode FastAPI service due to unsafe pickle deserialization of attacker-controlled request bodies combined with a nonce authentication bypass (nonce defaults to empty string, causing the check to be skipped).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.