CVE-2026-53519 is a pre-authentication path traversal vulnerability in Nezha Monitoring prior to version 2.0.13. The flaw is in the dashboard NoRoute fallback handler, where fallbackToFrontend classifies any request whose raw URL string begins with the dashboard prefix as an admin frontend asset request. Because the implementation uses a simple prefix check rather than validating path-segment boundaries, crafted requests can append traversal sequences immediately after the dashboard prefix. After prefix trimming and path normalization, the resulting path resolves outside the intended frontend asset directory and into application data files, which are then checked and served by the HTTP handler. This allows unauthenticated remote attackers to retrieve sensitive local files from the application working tree, including the main configuration file and potentially other application data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This 14-file repository is a local Docker A/B laboratory and supporting analysis for CVE-2026-53519 in Nezha Dashboard rather than a complete standalone PoC directory: README and GUIDE_EXPLOIT.md reference poc/poc-cve-2026-53519.ps1, negative-controls.ps1, and parse_users.py, but those files are not present in the supplied file listing. The executable material consists of PowerShell lab orchestration (lab.ps1), PowerShell raw-HTTP and HS256 JWT-forging helpers (lab-common.ps1), and a Python HTML-report generator (tools/build_report.py). Docker Compose deploys Nezha v2.0.12 at 127.0.0.1:9090 and v2.0.13 at 127.0.0.1:9091, with seeded data directories. The documented exploit abuses a missing path-segment boundary in fallbackToFrontend: a request beginning /dashboard../ passes strings.HasPrefix("/dashboard"), then TrimPrefix transforms it into ../data/... . Joining that value with the admin frontend path resolves to data/config.yaml or data/sqlite.db relative to /dashboard. The helper deliberately uses TcpClient and manually writes the HTTP request line so normal client URL canonicalization does not alter the traversal form. It can retrieve raw binary bodies, extract jwt_secret_key from YAML, create a correctly signed JWT using HMAC-SHA256, and retain evidence files. Impact is an unauthenticated read of data-directory files, including secrets and user records. Using the disclosed symmetric JWT secret and an administrator ID, the documented token payload impersonates the administrator and accesses /api/v1/profile and /api/v1/user. The repository also documents that direct multi-level traversal to /etc/passwd is expected to fail because net/http/ServeFile detects standalone .. URL segments, limiting the demonstrated read scope. The included patch analysis identifies the remediation as requiring /dashboard/ rather than /dashboard, using os.OpenRoot confinement for local files, and validating embedded-FS paths. Seed credentials and keys are explicitly lab-only, and the containers are loopback-bound.
This repository is a small standalone Python PoC for CVE-2026-53519 affecting Nezha Dashboard. The repo contains one exploit script (CVE-2026-53519.py), a README describing the exploit chain and usage, and a LICENSE file. The Python script is the sole entry point and performs a complete exploit chain rather than simple detection. Core capability: unauthenticated path traversal against a vulnerable Nezha Dashboard route using encoded /dashboard.. path manipulation. The script first requests /dashboard%2e%2e/data/config.yaml to extract jwt_secret_key with a regex. If a secret is not supplied on the command line, this step is automatic. Next, if a user ID is not supplied, it requests /dashboard%2e%2e/data/sqlite.db, saves it locally as t.db, opens it with sqlite3, and runs SELECT id FROM users ORDER BY id LIMIT 1 to obtain a valid user ID. It then forges an HS256 JWT containing user_id, empty ip, exp, and orig_iat claims, and finally sends the token as a Bearer token to /api/v1/profile to verify authenticated access. The exploit therefore provides credential material theft plus authentication bypass/privilege escalation. It does not deploy a shell or arbitrary command payload; instead, its payload is a forged JWT that grants application-level access. The README states this can lead to administrative control of the monitoring dashboard and connected agent nodes. Because the exploit includes a working automated chain and a usable authentication artifact, but not a customizable framework-grade payload system, OPERATIONAL is the best maturity fit.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown
A critical path traversal or file disclosure vulnerability in Nezha versions prior to 2.0.13 that allows access to data/config.yaml via /dashboard../data/config.yaml, exposing sensitive secrets such as jwt_secret_key and agent_secret_key.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.