Listen to this Post
How the CVE Works
The vulnerability exploits Kottster’s development mode, which lacks critical security checks. An attacker first repeatedly calls the unguarded `initApp` action. This creates a new root administrator account and returns a valid JWT token, bypassing authentication entirely. With this administrative token, the attacker then targets the `installPackagesForDataSource` action. This function constructs system commands using unsanitized user input from the request, allowing for command injection. By chaining these two flaws—reinitialization for auth bypass and command injection for execution—an unauthenticated attacker achieves full remote code execution on the development server, compromising the underlying host.
DailyCVE
Platform: Kottster
Version: <3.3.2
Vulnerability: Pre-auth RCE
Severity: Critical
date: 2024-XX-XX
Prediction: Patch Available
What Undercode Say:
Analytics
curl -X POST http://TARGET/initApp
curl -H "Authorization: Bearer JWT" -X POST http://TARGET/api/installPackagesForDataSource --data '{"packageManager":"npm; whoami "}'
// Malicious payload for command injection
{"packageManager": "npm; cat /etc/passwd "}
How Exploit:
1. Call `/initApp` repeatedly.
2. Capture new admin JWT.
3. Inject commands via `installPackagesForDataSource`.
Protection from this CVE
Upgrade to v3.3.2.
Isolate development instances.
Use production mode.
Impact:
Full system compromise.
Development mode only.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

