CVE-2023-40582General(find-exec_project / find-exec)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

find-exec is a utility to discover available shell commands. Versions prior to 1.0.3 did not properly escape user input and are vulnerable to Command Injection via an attacker controlled parameter. As a result, attackers may run malicious shell commands in the context of the running process. This issue has been addressed in version 1.0.3. users are advised to upgrade. Users unable to upgrade should ensure that all input passed to find-exec comes from a trusted source.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • find-exec

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-04); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
find-exec

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-04: 1Mentions · 2026-04-05: 1PoC Mentioned / Linked · 2026-04-05: 1Technical Details · 2026-04-05: 104-0404-05
Signal classification2 categories
General
150.0%
PoC
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-041
General1
2026-04-051
PoC1
Full discourse2 posts
  • Secwiser - Cyber Security Insights@Secwiserapp
    PoC

    CVE-2023-40582: Express flaw exposes root shell Detailed walkthrough of CVE-2023-40582: a Node.js Express app exposes /check-command, passing unsanitized user input to find-exec causing shell command injection. Attacker retrieved root shell via semicolon chaining, exposed by unauthenticated /check-command. Key lessons: sanitize inputs, least privilege, avoid exposing code, and authenticate endpoints. Read more: https://medium.com/@cyber_public_school/cve-2023-40582-walkthrough-proving-ground-oscp-8188b631f010?source=rss------cybersecurity-5 Discover the app: https://www.secwiser.com/app #ApplicationSecurity #WebSecurity #OWASP #VulnerabilityManagement #CyberSecurity #InfoSec #ExploitDetection #SecureCoding #NodeJS #ExpressJS #TrendingTech #Secwiser

    Post summary

    The post offers a detailed walkthrough of CVE-2023-40582, demonstrating how an unsanitized Express endpoint can be used for shell command injection and root privilege escalation.

    0000060
    19 followersView on X
  • ‘BBWriteups’@bbwriteup
    General

    "CVE-2023–40582 Walkthrough (Proving Ground-OSCP)" by Cyber Public School #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/@cyber_public_school/cve-2023-40582-walkthrough-proving-ground-oscp-8188b631f010

    Post summary

    The text refers to a Medium article titled "CVE-2023–40582 Walkthrough (Proving Ground-OSCP)" but provides no specific technical or exploit details beyond the title.

    00000100
    559 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfind-exec_projectfind-exec-node.js-

Explore more