A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp does not perform any validation on the file path parameters passed via the command line. The user-controlled input parameters are directly passed to the underlying file operation functions (fopen/ifstream/ofstream) for file reading and writing. An attacker can exploit this vulnerability by constructing a malicious path to read arbitrary readable files.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal proof-of-concept for CVE-2026-31156 affecting OpenPLC-v3. It contains no standalone exploit code beyond documentation and shell command examples. The README describes a path injection / arbitrary file read issue in the OpenPLC utility compiled from glue_generator.cpp. The flaw is local rather than remote: an attacker who can run the binary may supply an arbitrary file path as an input argument, causing the program to open and parse that file without validating path legitimacy or sensitivity. If lines in the file match the parser's expected format '(<varType>,<varName>,', the extracted values are printed to stdout, disclosing file contents. Repository structure is very small: README.md documents the vulnerability, impact, prerequisites, and exploitation steps; poc.txt contains shell commands showing how to compile the upstream source, create test files, and invoke the vulnerable binary against both a benign file and /etc/passwd via a relative traversal path. There is no custom payload, shell, or post-exploitation logic. The exploit capability is limited to local information disclosure through arbitrary readable file access under the privileges of the executing user. Because the repository only provides procedural PoC steps and not a reusable exploit program, its maturity is best classified as POC.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.