CVE-2024-23738

CRITICAL

Postman < 10.22 - Remote Code Execution via RunAsNode Configuration

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2024-23738. PoCs published by giovannipajeu1.

AI-analyzed exploit summary The repository provides a technical writeup for CVE-2024-23738, detailing how a remote attacker can execute arbitrary code in Postman on macOS via the RunAsNode and enableNodeClilnspectArguments settings. It references the electroniz3r tool for vulnerability validation and includes screenshots of the exploitation process.

Description

An issue in Postman version 10.22 and before on macOS allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. NOTE: the vendor states "we dispute the report's accuracy ... the configuration does not enable remote code execution.."

Exploits (2)

nomisec WRITEUP 1 stars
by giovannipajeu1 · poc
https://github.com/giovannipajeu1/CVE-2024-23738

The repository provides a technical writeup for CVE-2024-23738, detailing how a remote attacker can execute arbitrary code in Postman on macOS via the RunAsNode and enableNodeClilnspectArguments settings. It references the electroniz3r tool for vulnerability validation and includes screenshots of the exploitation process.

Classification
Writeup 80%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Postman through 10.22 on macOS
No auth needed
Prerequisites: Access to the target system · Postman application installed
devstral-2 · analyzed Feb 19, 2026 Full analysis →
inthewild WRITEUP
poc
https://github.com/v3x0r/cve-2024-23738

The repository provides a technical writeup for CVE-2024-23738, detailing how a remote attacker can execute arbitrary code in Postman on macOS via the RunAsNode and enableNodeClilnspectArguments settings. It references the electroniz3r tool for vulnerability validation and includes screenshots of the exploitation process.

Classification
Writeup 80%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Postman through 10.22 on macOS
No auth needed
Prerequisites: Postman installed on macOS · Access to the target system to modify settings
devstral-2 · analyzed Feb 23, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.1275
EPSS Percentile 94.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
postman/postman < 10.22
Published Jan 28, 2024
Tracked Since Feb 18, 2026