Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
MetabaseRCE_CVE-2023-38646 — Proof-of-concept exploit for Metabase pre-auth RCE (CVE-2023-38646) that retrieves setup token and executes arbitrary commands via base64-encoded payload. | Kitploit
Tools/GitHubGitHub/shisones/metabaserce_cve-2023-38646
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed TeamingRemote Access Tool
GitHubshisones/metabaserce_cve-2023-38646

MetabaseRCE_CVE-2023-38646

Proof-of-concept exploit for Metabase pre-auth RCE (CVE-2023-38646) that retrieves setup token and executes arbitrary commands via base64-encoded payload.

View Repository
12 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Metabase Pre-Auth RCE (CVE-2023-38646) PoC

A proof of concept of CVE-2023-38646, a Metabase exploit that allows user to do Remote Code Execution utilizing the setup token found in /api/session/properties to send a payload encoded in base64

Usage

./MetabaseRCE_CVE-2023-38646 -u [target url] -t [target token] -c [command]

Download Tool