CVE-2024-28397Exploit

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Technical details provided in 3 signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-01-31: 3PoC Mentioned / Linked · 2026-01-31: 3Exploit Tool / Code · 2026-01-31: 1Technical Details · 2026-01-31: 301-31
Signal classification1 categories
Exploit
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • 0xdf@0xdf_
    Exploit

    CodeTwo from @hackthebox_eu features a js2py sandbox escape via CVE-2024-28397, MD5 hash cracking from SQLite, and abusing npbackup-cli sudo permissions to read root's SSH key from backups. https://0xdf.gitlab.io/2026/01/31/htb-codetwo.html

    Post summary

    The blog post details an exploit of CodeTwo via CVE-2024-28397, highlighting a js2py sandbox escape and additional vulnerabilities such as MD5 cracking and privilege abuse to read root SSH keys.

    0905492.5K
    25.9K followersView on X
  • sckull@sckull_
    Exploit

    HackTheBox - CodeTwo 🧠 RCE en js2py (CVE-2024-28397) 🔑 Credenciales en base de datos SQLite 🛠️ Privesc via sudo + npbackup-cli https://sckull.github.io/posts/codetwo/

    Post summary

    The post describes a proof‑of‑concept that CVE‑2024‑28397 in js2py allows remote code execution, exposes credentials in an SQLite database, and enables privilege escalation via sudo and npbackup‑cli.

    00000130
    177 followersView on X
  • strikoder@Strikoder
    Exploit

    New HackTheBox walkthrough: CodePartTwo Exploiting js2py CVE-2024-28397 sandbox escape for initial access, then privilege escalation through NPBackup misconfiguration to extract root SSH keys. Full breakdown from recon to root. https://youtu.be/dQqKRxrY4IU #HackTheBox #OSCP https://t.co/0aT5MNIKcb

    Post summary

    The post provides a walkthrough showing exploitation of CVE-2024-28397 through a sandbox escape, followed by privilege escalation via an NPBackup misconfiguration to obtain root SSH keys; no patch or mitigation is discussed.

    00000116
    15 followersView on X

Explore more