CVE-2024-40348Exploit(bazarr / bazarr)

LOWCVSS 8.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for bazarr bazarr systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory traversal.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bazarr

Threat summary

  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
bazarr

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-09: 1PoC Mentioned / Linked · 2026-07-09: 1Exploit Tool / Code · 2026-07-09: 1Technical Details · 2026-07-09: 107-09
Signal classification1 categories
Exploit
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Hacking Team@HackingTeam77
    Exploit

    🚨 CVE-2024-40348 🚨 👉 This is a bulk scanning and exploitation tool for CVE-2024-40348: Bazaar v1.4.3 allows unauthenticated attackers to execute a directory traversal. This vulnerability was discovered by 4rdr. 🔗 Download : https://github.com/bigb0x/CVE-2024-40348 https://t.co/W0g1prYxmH

    Post summary

    The post announces a GitHub‑hosted exploitation tool for CVE‑2024‑40348, highlighting a directory traversal flaw and providing code for potential attacks.

    00000132
    1.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbazarrbazarr---

Explore more