CVE-2024-48990PoC(needrestart_project / needrestart)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-427

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • needrestart

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 3 signals
  • Technical details provided in 3 signals
  • Exploit: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Products
needrestart

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-21: 3PoC Mentioned / Linked · 2026-03-21: 3Technical Details · 2026-03-21: 303-21
Signal classification2 categories
PoC
266.7%
Exploit
133.3%
Referenced assets2 URLs
Full discourse3 posts
  • 0xdf@0xdf_
    PoC

    Conversor from @hackthebox_eu features XSLT injection and os.path.join abuse for file write, and CVE-2024-48990 in needrestart (plus a config GTFObin) for root. https://0xdf.gitlab.io/2026/03/21/htb-conversor.html

    Post summary

    The post discloses a CVE‑2024‑48990 flaw involving XSLT injection and file‑write via os.path.join abuse, with details pointing to a PoC hosted on the linked blog.

    18039122.5K
    26.1K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    PoC

    HTB “Conversor” write-up: Flask app converting Nmap XML to HTML is abused via XSLT injection + os.path.join traversal to drop cron-executed Python shells, gain www-data, crack MD5 creds → fismathack, then escalate to root using CVE-2024-48990 (needrestart / PYTHONPATH). #HackTheBox #XSLT #PrivilegeEscalation #Linux #Flask https://0xdf.gitlab.io/2026/03/21/htb-conversor.html

    Post summary

    A HackTheBox write‑up demonstrates how a Flask app was abused with XSLT injection and path traversal to drop cron‑executed shells, then leveraged CVE‑2024‑48990 to achieve root, accompanied by a link to the full PoC.

    0000045
    309 followersView on X
  • sckull@sckull_
    Exploit

    HackTheBox - Conversor 🛤️ Path Traversal y Arbitrary File Write ⏰ Acceso inicial a traves de Cronjob para scripts Python 🔑 Credenciales en base de datos 🚀 Escalada de privilegios via CVE-2024-48990 https://sckull.github.io/posts/conversor/

    Post summary

    The write‑up outlines how HackTheBox's Conversor challenge leverages CVE-2024-48990 for privilege escalation, with path traversal and arbitrary file write, and provides a link to a detailed post.

    0000095
    177 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appneedrestart_projectneedrestart---

Explore more