CVE-2019-10758 is a remote code execution vulnerability in mongo-express versions before 0.54.0. Endpoints using the toBSON method misuse the vm dependency to execute commands in an unsafe environment, allowing attackers to execute code remotely. The vulnerability has been exploited in Sysrv-hello and Gitpaste-12 cryptomining campaigns.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This 34-file repository is a deliberately vulnerable training lab for CVE-2019-10758, not a standalone exploit framework. It includes a working-style HTTP exploit example in the English and Chinese app READMEs, but no automated exploit client. The example submits JavaScript in the document parameter to POST /checkValid. The documented vulnerable toBSON path evaluates that input in Node.js vm; the payload reaches the host process, imports child_process, and executes touch /tmp/success. No reverse shell, persistence, exfiltration, or host/container escape payload is supplied, and execution was not independently verified. isoloom.yml is the canonical lab specification. app/ contains the vendored Vulhub walkthrough and minimal Compose deployment. base/mongo-express/0.53.0/ contains the image Dockerfile and Bash entrypoint, showing Node.js 12, mongo-express 0.53.0, and empty Basic-auth credentials. The active lab uses published vulhub/mongo-express:0.53.0 and mongo:3.4 images rather than building that Dockerfile. MongoDB is supporting infrastructure, not a separately exploited target. UPSTREAM.md records Vulhub commit 8fd63916f7a8711e2e01dda0d27237e4d6175d38 as vendored provenance; the analyzed repository's original URL, analyzed ref, and archive size were not supplied, so those metadata fields are left empty or zero. .isoloom/ contains generated Docker Compose, Kubernetes deployments/services/network policies/check jobs, a Vagrant Docker-host VM, Proxmox Terraform, and Terraform deployments for AWS, Azure, DigitalOcean, GCP, Linode, and OCI. Docker assigns web 10.60.247.10 and MongoDB 10.60.247.20 on 10.60.247.0/24. Web TCP 8081 is published; MongoDB TCP 27017 stays internal. Docker sidecars remove default routes, while Kubernetes policies restrict outbound access to namespace peers and cluster DNS. Cloud firewalls restrict SSH and published web access to a configured allowed_cidr. These isolation measures can prevent callbacks to external shell listeners but do not remove the RCE vulnerability. checks/express.sh and six generated shell runners check HTTP identity, database listing, service reachability, and outbound isolation; they do not test exploitation of /checkValid. GitHub workflows validate generated infrastructure and running lab health, and register approved labs using secret-configured backend/token URLs that are not visible in the supplied files. The 17 code/build files comprise eight shell scripts, seven Terraform files, one Ruby Vagrantfile, and one Dockerfile; JavaScript appears only as an embedded documentation payload. Remaining files are configuration, metadata, licensing, or documentation. Image tags and several upstream downloads are not immutable pins. The rm -rf commands shown are scoped CI cleanup and lab reprovisioning operations, not evidence of a fake exploit.
This repository is a proof-of-concept (PoC) exploit for CVE-2019-10758, a remote code execution vulnerability in mongo-express <=0.53.0. The repository contains three files: a README.md with setup and exploitation instructions, a main.js script that crafts the exploit payload, and a package-lock.json for dependencies. The exploit works by sending a specially crafted payload to the /checkValid endpoint of a locally running mongo-express instance, leveraging server-side JavaScript injection to execute arbitrary system commands. The provided payload demonstrates launching the Calculator app on macOS, but any command could be executed. The exploit requires the vulnerable mongo-express to be running with default credentials and accessible on http://localhost:8081. The main.js file is the core exploit script, while the README provides both a cURL-based and script-based exploitation method. No detection or fake code is present; this is a functional PoC exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability involving the ToBSON method in Mongo-Express. Multiple matching scanner IPs have associated attempt tags.
A specific vulnerability included among the exploit targets used by the Gitpaste-12/X10-unix cryptomining worm.
A remote code execution vulnerability in MongoDB mongo-express that has been actively exploited in the wild.
A remote code execution vulnerability in Mongo Express that the content identifies as used by Sysrv.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.