
Proof-of-concept exploit for CVE-2024-23742 in Loom for macOS. Validates vulnerability and injects arbitrary code via RunAsNode settings to gain a remote shell.
An issue in Loom through 0.196.1 on macOS allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

With this tool, we can check if the App is Vulnerable:
After validation, we can inject our code, and get a shell
Enjoy Your Shell :)