Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
The repository contains a standalone Python 3 proof of concept, a corresponding Nuclei YAML template, an MIT license, and documentation for CVE-2026-69137. The vulnerability is an authenticated SSRF in SuiteCRM's CalendarAccount testConnection action when the caldav_basic source processes an unvalidated server_url. CVE-2026-69137.py uses only Python standard-library modules, optionally authenticates through the legacy Users/Authenticate request or accepts an existing Cookie header, then posts a crafted CalendarAccount/testConnection request to /index.php. It interprets INVALID_ARGUMENT/not allowed as likely patched and CONNECTION_TEST_FAILED or a successful response as confirmation that the server processed the supplied URL. The configurable --server-url parameter can target loopback or internal HTTP services; the safe default is the unavailable loopback endpoint 127.0.0.1:1. CVE-2026-69137.yaml performs the same two-request workflow in Nuclei, validating a successful login session and matching the expected 422 CONNECTION_TEST_FAILED network-error response. The repository is primarily a PoC with a detection-oriented template, rather than a general-purpose exploitation framework or a payload that obtains code execution.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.