{"id":"CVE-2023-52251","title":"An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages","summary":"An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages. No fixed release is available; the project has had no com…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-94"],"vendor":"provectus","product":"ui","affected":["ui >= 0.4.0, <= 0.7.1"],"published":"2024-01-25","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:17:43.673","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-52251","references":[{"url":"http://packetstormsecurity.com/files/177214/Kafka-UI-0.7.1-Command-Injection.html","label":"cve@mitre.org"},{"url":"https://github.com/BobTheShoplifter/CVE-2023-52251-POC","label":"cve@mitre.org"},{"url":"https://github.com/github/advisory-database/issues/9400","label":"cve@mitre.org"},{"url":"https://github.com/google/osv.dev/issues/5988","label":"cve@mitre.org"},{"url":"https://github.com/kafbat/kafka-ui/commit/11a57d14","label":"cve@mitre.org"},{"url":"https://github.com/provectus/kafka-ui/blob/v0.7.2/kafka-ui-api/src/main/java/com/provectus/kafka/ui/emitter/MessageFilters.java","label":"cve@mitre.org"},{"url":"http://packetstormsecurity.com/files/177214/Kafka-UI-0.7.1-Command-Injection.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/BobTheShoplifter/CVE-2023-52251-POC","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2024-11-13T15:44:13.987270Z"},"epss":0.8684,"epssPercentile":0.99737,"exploits":{"github":1,"githubRepos":["https://github.com/BobTheShoplifter/CVE-2023-52251-POC"],"metasploit":["exploit/linux/http/kafka_ui_unauth_rce_cve_2023_52251"],"nuclei":["CVE-2023-52251"],"checkedAt":"2026-09-23T07:13:27.502Z"},"ingestedAt":"2026-09-08T19:08:49.636Z","slug":"CVE-2023-52251","body":"## Overview\n\nAn issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages. No fixed release is available; the project has had no commit since 2024-04-08.\n\n## Affected\n\n- `ui >= 0.4.0, <= 0.7.1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":78,"depthScoreParts":{"impact":48.4,"likelihood":17.4,"exploitation":12,"ransomware":0},"changes":[]}