Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-28397-exploit — js2py <= 0.74 sandbox escape (CVE-2024-28397) | Kitploit
Tools/GitHubGitHub/3z-p0wn/cve-2024-28397-exploit
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationPayload Development
GitHub3z-p0wn/cve-2024-28397-exploit

CVE-2024-28397-exploit

js2py <= 0.74 sandbox escape (CVE-2024-28397)

View Repository
8 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

js2py Sandbox Escape (CVE-2024-28397)

Exploit for remote command execution (RCE) via sandbox escape in js2py <= 0.74.

Allows arbitrary code execution on the host system through insecure JavaScript evaluation.


Vulnerability

  • CVE: CVE-2024-28397
  • Component: js2py
  • Affected versions: <= 0.74
  • Impact: Remote Code Execution
  • Vector: JavaScript sandbox escape
  • Vulnerability analysis: CVE-2024-28397-js2py-Sandbox-Escape

Features

  • Sandbox escape
  • Command execution via subprocess.Popen
  • Reverse shell
  • No external dependencies on the target

Requirements

  • Python 3.8+
  • Access to a vulnerable endpoint that evaluates JS with js2py

Dependencies:

pip install -r requirements.txt

Usage

python3 exploit.py -U http://target_url -H IP -P PORT

Legal disclaimer

This project is provided for educational purposes and for authorized security audits only.

The author is not responsible for any misuse of this tool.

Download Tool