Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-40146_Exploit_Jar — Java-based exploit for Apache Batik SSRF to RCE (CVE-2022-40146) with payload generation via jar and ecmascript, enabling remote class loading attacks. | Kitploit
Tools/GitHubGitHub/cckuailong/cve-2022-40146_exploit_jar
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHubcckuailong/cve-2022-40146_exploit_jar

CVE-2022-40146_Exploit_Jar

Java-based exploit for Apache Batik SSRF to RCE (CVE-2022-40146) with payload generation via jar and ecmascript, enabling remote class loading attacks.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
31663 years agoReviewed by Kitploit
Share

Apache Batik SSRF to RCE Jar Exploit

Component link

https://github.com/apache/xmlgraphics-batik

Blog

https://www.zerodayinitiative.com/blog/2022/10/28/vulnerabilities-in-apache-batik-default-security-controls-ssrf-and-rce-through-remote-class-loading

Usage

  • Modify the line 11 in src/main/java/com.poc.Poc.java to change the command.
  • Run mvn clean package
  • Exploit can be found in target/

Then you need to navigate to the Poc/ to use this exploit jar.

Poc contains:

  • SSRF
  • RCE via jar
  • RCE via ecmascript
Download Tool