A zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write arbitrary files outside the intended directories via supplying a crafted import.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, self-contained proof-of-concept exploit for CVE-2026-30345 affecting CTFd versions earlier than 3.8.2. It contains one Python exploit generator and a README with setup, usage, and testing instructions. The Python script is the main entry point and does not directly attack a live target over HTTP; instead, it prepares a malicious backup ZIP for later upload through the CTFd admin backup import feature. Repository structure: README.md documents the vulnerability, prerequisites, test workflow, and expected impact. cve_2026_30345_bashrc_poc.py is the only code file and implements the exploit logic. The script accepts a legitimate extracted db/ directory from a real CTFd backup export, validates that alembic_version.json exists, copies the full db/ tree into a new ZIP, and then adds a crafted archive member named uploads//{target}/.bashrc. The comments indicate this double-slash path is intended to bypass import validation and achieve arbitrary file write during backup import. Main exploit capability: arbitrary file write leading to persistence and code execution. The generated .bashrc payload is a bash reverse shell stub that connects to an operator-supplied IP and port using /dev/tcp and runs in the background whenever an interactive shell starts. This gives the operator a shell when the affected user later opens bash. By default the target user is root, but the script allows changing the target username. The payload also logs execution to /tmp/.cve_2026_30345.log. Operational flow: the operator exports a legitimate backup from the same CTFd instance, extracts it, runs the Python script with --db-dir and --attacker-ip, receives a malicious ZIP, uploads that ZIP through Admin Panel -> Config -> Backup -> Import, and then waits for or forces an interactive shell start (for example via docker exec -it ctfd bash) so the injected .bashrc executes. Because the exploit relies on a real backup export from the same instance, it is more than a theoretical PoC and is operational, though the payload is basic and hardcoded rather than framework-driven. No exploit framework is used. The code is straightforward Python using argparse, pathlib, zipfile, and textwrap. The exploit is not a scanner or detection script; it is a weaponized archive builder for a specific arbitrary file write condition in CTFd backup import.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.