CollabPlatform is a full-stack, real-time doc collaboration platform. In all versions of CollabPlatform, the Appwrite project used by the application is misconfigured to allow arbitrary origins in CORS responses while also permitting credentialed requests. An attacker-controlled domain can issue authenticated cross-origin requests and read sensitive user account information, including email address, account identifiers, and MFA status. The issue did not have a fix at the time of publication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a minimal proof-of-concept for CVE-2026-27579 (GHSA-qh5m-p8jh-hx88), described as a CORS misconfiguration in karnop's realtime-collaboration-platform using an Appwrite backend. Structure: - CVE-2026-27579.js: Single browser-side JavaScript snippet that issues a credentialed fetch() to an Appwrite API endpoint (/v1/account) and parses/prints the JSON response. - README.md: Detailed write-up of the vulnerability, impact, and remediation guidance; includes the same PoC snippet and screenshots. - LICENSE: MIT. Exploit capability/purpose: - Demonstrates authenticated data exposure via CORS: if the target server allows arbitrary origins (or reflects Origin) while also allowing credentials, an attacker can host a malicious page that, when visited by a logged-in victim, reads sensitive account data returned by the Appwrite /v1/account endpoint. - The provided code logs the retrieved data to the console; it does not include an automated exfiltration channel, persistence, or post-exploitation actions. No framework integration, no scanning/detection logic, and no additional payloads beyond the credentialed cross-origin request.
Repository contains a single Python proof-of-concept exploit (CollabPlatform.py) plus a README. The exploit is a Flask-based malicious web server that serves a phishing page at '/' which runs JavaScript to issue a credentialed CORS request (fetch with credentials: 'include') to the Appwrite Cloud Account API endpoint 'https://cloud.appwrite.io/v1/account' using hardcoded Appwrite headers (notably X-Appwrite-Project: 6981d34b0036b9515a07). If the target Appwrite deployment is misconfigured to reflect arbitrary Origin while allowing credentials, the browser will allow the script to read the JSON response containing sensitive account data. The script then exfiltrates that data via a POST to the attacker endpoint '/collect' (mode: no-cors, keepalive) where the Flask handler prints the stolen data and appends it to 'stolen_accounts.txt'. After exfiltration, the victim is redirected to Google to mask the activity. Operation requires social engineering (victim must visit the attacker URL while logged in) and a vulnerable CORS configuration on the target endpoint. No framework integration is present; this is a standalone PoC.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.