CVE-2021-25646 is a code injection vulnerability in Apache Druid 0.20.0 and earlier. A specially crafted request can force execution of user-provided JavaScript despite server configuration disabling JavaScript execution. Successful exploitation permits code execution on the host with the privileges of the Druid server process. The vulnerability description specifies an authenticated attacker, while campaign reporting describes unauthenticated exploitation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This is a deliberately vulnerable training environment with a valid manual exploit, not a standalone exploit program or an exploitation-framework module. Its 31 files include 23 scripts, build recipes, infrastructure definitions, and workflow/configuration files; JavaScript exploit code is embedded in the two app walkthroughs. The documented sampler POST abuses an empty JSON property to enable otherwise-disabled JavaScript, then accesses Java classes to execute id and return its output. Execution has the Druid process's privileges; no privilege escalation, persistence, credential theft, or reverse shell is implemented. The root isoloom.yml defines one Druid machine and an offline lab network. app/ contains the vendored English/Chinese exploit walkthroughs and minimal Docker Compose setup. base/ contains the OpenJDK 8-based Druid image recipe. Generated .isoloom/ artifacts provide Docker Compose, Kubernetes deployments/services/network policies and check jobs, a multi-provider Vagrant Docker host, Proxmox Terraform, and six cloud Terraform deployments. checks/version.sh fingerprints the version and checks sampler availability without submitting the exploit. Generated checks verify console readiness and blocked external connectivity. .github/workflows/ validates and publishes the lab, .ctf/ supplies challenge metadata, and UPSTREAM.md records provenance from Vulhub commit 8fd63916f7a8711e2e01dda0d27237e4d6175d38. Authentication requirements are deployment-dependent: upstream documentation describes authenticated exploitation, while this lab exposes a no-login console. Docker isolation removes the target's default route, and Kubernetes policies restrict egress when enforced by the cluster network plugin, so external callback payloads may not work unchanged. The legacy app Compose file lacks those isolation controls, and generated Kubernetes exposes a LoadBalancer service. Cloud ingress is restricted by an operator-supplied CIDR. Provisioning downloads Docker installation code, and image dependencies are tag-pinned rather than digest-pinned. Cleanup rm -rf commands belong to CI/VM provisioning and do not indicate a fake exploit. No execution or runtime validation was performed. The analyzed repository URL, reference, and archive size were not supplied; empty strings and zero represent unavailable metadata, not the documented upstream repository.
This repository contains a Python exploit script (druid_rce.py) and a README.md file. The exploit targets Apache Druid servers vulnerable to CVE-2021-25646 (versions prior to 0.20.1), which allows remote code execution via JavaScript code injection in sampler requests. The script takes a target URL and a shell command as arguments, crafts a malicious JSON payload that injects JavaScript into the Druid indexer API (/druid/indexer/v1/sampler), and executes the specified command on the target server. The output of the command is extracted from the API response and displayed to the user. The exploit requires the target Druid instance to be accessible over the network and the indexer API to be exposed. The code is operational and provides direct command execution capabilities, making it suitable for penetration testing and red teaming against vulnerable Druid deployments.
This repository is a Go-based proof-of-concept exploit for CVE-2021-25646, a critical remote code execution vulnerability in Apache Druid. The exploit consists of a main entry point (main.go) that provides an interactive shell interface, allowing the user to execute arbitrary commands on a vulnerable Druid server. The exploit works by sending a specially crafted JSON payload to the /druid/indexer/v1/sampler HTTP endpoint, abusing the indexer component's task API to inject and execute commands via Java's Runtime.exec. The payload is constructed in utils/payload.go and leverages a JavaScript function in the JSON to execute the supplied command and return its output. The exploit supports optional proxying and is designed for interactive use. The repository includes a README with usage instructions, technical details, and references. No weaponized or automated post-exploitation features are present; this is a functional proof-of-concept for manual exploitation.
This repository is an exploit and detection tool for Apache Druid CVE-2021-25646, a remote code execution vulnerability. The main logic resides in 'vul/druid/druidScan.go', which provides both detection and exploitation capabilities. The tool accepts a target (domain or IP:port) or a file with multiple targets, and sends a crafted POST request to the '/druid/indexer/v1/sampler' endpoint. The payload leverages a JavaScript function to execute arbitrary system commands on the server via Java's Runtime.exec. If no command is specified, it defaults to 'id' for detection; otherwise, any command (including reverse shell payloads) can be executed. The tool is written in Go, with supporting modules for colored output and file handling. The exploit is operational and can be used for both vulnerability scanning and actual exploitation, including obtaining a shell on the target system. No hardcoded IPs or domains are present; the tool is designed for user-supplied targets.
This repository contains a single Metasploit module (modules/exploits/linux/http/apache_druid_js_rce.rb) that exploits CVE-2021-25646, a remote code execution vulnerability in Apache Druid versions prior to 0.20.1. The exploit leverages the ability to enable and execute user-supplied JavaScript in a single HTTP POST request to the /druid/indexer/v1/sampler endpoint. By crafting a malicious payload, the attacker can execute arbitrary system commands on the Druid server. The module supports both staged payloads (e.g., meterpreter reverse shell via curl/wget) and in-memory command execution (e.g., bash reverse shell). The exploit is weaponized, allowing for easy payload customization within the Metasploit framework. The default target port is 8888, and the attack is possible when authentication is not enabled (default configuration). The code is well-structured, with clear separation of command execution, vulnerability checking, and exploitation logic.
This repository contains a Python exploit script (CVE-2021-25646.py) targeting Apache Druid servers vulnerable to CVE-2021-25646. The exploit works by sending a crafted POST request to the '/druid/indexer/v1/sampler' endpoint of a Druid instance, injecting a user-supplied shell command into a JavaScript function executed by the server. The README provides usage instructions, including how to use the exploit to write and execute a reverse shell script on the target. The exploit is operational, allowing arbitrary command execution, and can be used for post-exploitation activities such as file manipulation or establishing a reverse shell. The main fingerprintable endpoint is the Druid API path '/druid/indexer/v1/sampler', and the exploit manipulates files such as '/tmp/1.sh' and '/etc/passwd' on the target system.
This repository contains a proof-of-concept (PoC) exploit for CVE-2021-25646, a remote code execution vulnerability in Apache Druid versions prior to 0.20.1. The exploit is implemented in Python (cve-2021-25646.py) and targets the /druid/indexer/v1/sampler HTTP endpoint, which is accessible without authentication in default Druid installations. The script sends a specially crafted JSON payload that leverages a JavaScript transform in the Druid ingestion spec to execute arbitrary system commands on the server. By default, it attempts to execute a 'ping' command to a DNS log domain (t6gx5w.dnslog.cn), allowing the attacker to verify successful code execution via DNS logs. The README.md provides usage instructions and context about the vulnerability. The exploit demonstrates RCE but does not provide a weaponized or post-exploitation payload; it is intended for verification and demonstration purposes.
This repository contains a Python exploit script (cve-2021-25646.py) targeting Apache Druid servers vulnerable to CVE-2021-25646 (versions < 0.20.1). The exploit leverages a vulnerability in the /druid/indexer/v1/sampler API endpoint, where user-supplied JavaScript code is executed in the context of the server, allowing arbitrary system command execution via java.lang.Runtime.getRuntime().exec(). The script accepts a target URL and a command to execute, constructs a malicious JSON payload, and sends it via HTTP POST to the vulnerable endpoint. The README provides usage instructions and references a proof-of-concept article. The exploit is operational, requiring the attacker to specify the target and command, and is capable of executing arbitrary commands on the server. No hardcoded IPs or domains are present, but the endpoint /druid/indexer/v1/sampler is fingerprintable. The repository is straightforward, containing only the exploit script and a README.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A specific CVE included in TuxBot's exploit VM set, but the VM is completely broken due to a magic mismatch and never executes.
A remote code execution vulnerability affecting Apache Druid 0.20.0 and earlier. The article describes crafted requests that execute attacker-controlled JavaScript with Druid server privileges, even when JavaScript execution is disabled. The campaign exploited this flaw to deploy Lucifer malware and subsequently a cryptominer.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.