---
id: CVE-2023-52251
title: >-
  An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote
  attackers to execute arbitrary code via the q parameter of
  /api/clusters/local/topics/{topic}/messages
summary: >-
  An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote
  attackers to execute arbitrary code via the q parameter of
  /api/clusters/local/topics/{topic}/messages. No fixed release is available;
  the project has had no com…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: provectus
product: ui
affected:
  - 'ui >= 0.4.0, <= 0.7.1'
published: '2024-01-25'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:17:43.673'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-52251'
references:
  - url: >-
      http://packetstormsecurity.com/files/177214/Kafka-UI-0.7.1-Command-Injection.html
    label: cve@mitre.org
  - url: 'https://github.com/BobTheShoplifter/CVE-2023-52251-POC'
    label: cve@mitre.org
  - url: 'https://github.com/github/advisory-database/issues/9400'
    label: cve@mitre.org
  - url: 'https://github.com/google/osv.dev/issues/5988'
    label: cve@mitre.org
  - url: 'https://github.com/kafbat/kafka-ui/commit/11a57d14'
    label: cve@mitre.org
  - url: >-
      https://github.com/provectus/kafka-ui/blob/v0.7.2/kafka-ui-api/src/main/java/com/provectus/kafka/ui/emitter/MessageFilters.java
    label: cve@mitre.org
  - url: >-
      http://packetstormsecurity.com/files/177214/Kafka-UI-0.7.1-Command-Injection.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/BobTheShoplifter/CVE-2023-52251-POC'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2024-11-13T15:44:13.987270Z'
epss: 0.8684
epssPercentile: 0.9974
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/BobTheShoplifter/CVE-2023-52251-POC'
  metasploit:
    - exploit/linux/http/kafka_ui_unauth_rce_cve_2023_52251
  nuclei:
    - CVE-2023-52251
  checkedAt: '2026-09-25T08:20:42.600Z'
ingestedAt: '2026-09-08T19:08:49.636Z'
---

## Overview

An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages. No fixed release is available; the project has had no commit since 2024-04-08.

## Affected

- `ui >= 0.4.0, <= 0.7.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
