{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agradio_projectgradiopython/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gradio_project:gradio:*:*:*:*:*:python:*:*"],"_cs_cves":[{"cvss":6.5,"id":"CVE-2024-51751"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["XWiki (all versions prior to patch)"],"_cs_severities":["low"],"_cs_tags":["vulnerability","rce","web-application"],"_cs_type":"advisory","_cs_vendors":["XWiki"],"content_html":"\u003cp\u003eXWiki, an open-source enterprise wiki platform, contains a critical vulnerability identified as CVE-2024-51751. This flaw permits an authenticated remote attacker to execute arbitrary code within the context of the application. The vulnerability is triggered through the manipulation of user-supplied input that is insufficiently sanitized before processing, allowing the attacker to escape the expected application sandbox. Given the nature of XWiki's architecture, which often involves integrations with internal business processes and administrative functions, successful exploitation grants the attacker significant control over the application server. Defenders should focus on monitoring for unauthorized administrative access and suspicious system calls originating from the XWiki service account.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2024-51751 leads to a full system compromise, allowing an attacker to execute arbitrary commands, access sensitive data within the wiki, and potentially pivot into the internal network environment. The target scope includes any organization deploying XWiki instances where external or internal users hold valid (or low-privileged) credentials.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch XWiki instances to the latest version immediately to mitigate CVE-2024-51751.\u003c/li\u003e\n\u003cli\u003eReview XWiki access logs for unusual patterns of authenticated activity, particularly involving administrative or configuration-related endpoints.\u003c/li\u003e\n\u003cli\u003eRestrict access to the XWiki administration interface to trusted IP ranges or VPN-only access.\u003c/li\u003e\n\u003cli\u003eImplement EDR or audit logging on the XWiki host to monitor for unexpected process creation (e.g., cmd.exe, /bin/sh, or /usr/bin/python) originating from the web server application process.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-21T13:51:00Z","date_published":"2026-09-21T13:51:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-xwiki-rce/","summary":"An authenticated remote code execution vulnerability (CVE-2024-51751) in XWiki allows authenticated attackers to execute arbitrary code on the underlying host system.","title":"Remote Code Execution Vulnerability in XWiki","url":"https://feed.craftedsignal.io/briefs/2026-09-xwiki-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:gradio_project:gradio:*:*:*:*:*:python:*:*","version":"https://jsonfeed.org/version/1.1"}