CVE-2024-28397
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 5.3epss 4.5%
from disclosure to weapon0 days
Published on NVDJun 20
1st PoCJun 19
metasploit+130d
exploitation probability
4.5%top 9% of all CVEs
observed exploitation
nono source reports it
19 public exploit(s)
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected products
n/a · n/apublic PoCs found — 19
exploitdbwww.exploit-db.com/exploits/52532unverifiedgithubgithub.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape★ 72githubgithub.com/naclapor/CVE-2024-28397★ 12githubgithub.com/GhostOverflow/CVE-2024-28397-command-execution-poc★ 5githubgithub.com/xeloxa/CVE-2024-28397-Js2Py-RCE-Exploit★ 2githubgithub.com/L1337Xi/CVE-2024-28397-Exploit-Automation★ 2githubgithub.com/releaseown/exploit-js2py★ 1githubgithub.com/somisec/CVE-2024-28397-Reverse-Shell★ 1githubgithub.com/harutomo-jp/CVE-2024-28397-RCE★ 1githubgithub.com/s0m1s0ng/CVE-2024-28397-Reverse-Shell★ 1githubgithub.com/CYBER-WARRIOR-SEC/CVE-2024-28397-js2py-Sandbox-Escape★ 0githubgithub.com/ExtremeUday/Remote-Code-Execution-CVE-2024-28397-pyload-ng-js2py-★ 0githubgithub.com/3z-p0wn/CVE-2024-28397-exploit★ 0githubgithub.com/y0naldez/CVE-2024-28397-Js2Py-RCE★ 0githubgithub.com/D3ltaFormation/CVE-2024-28397-Js2Py-RCE★ 0githubgithub.com/0xDTC/js2py-Sandbox-Escape-CVE-2024-28397-RCE★ 0githubgithub.com/vitaciminIPI/CVE-2024-28397-RCE★ 0githubgithub.com/Udayveer17/Remote-Code-Execution-CVE-2024-28397-pyload-ng-js2py-★ 0githubgithub.com/Naved124/CVE-2024-28397-js2py-Sandbox-Escape★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.