CVE-2024-23738

CRITICAL

Postman < 10.22 - Remote Code Execution

Title source: rule

Description

An issue in Postman version 10.22 and before on macOS allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. NOTE: the vendor states "we dispute the report's accuracy ... the configuration does not enable remote code execution.."

Exploits (2)

nomisec WRITEUP 1 stars
by giovannipajeu1 · poc
https://github.com/giovannipajeu1/CVE-2024-23738
inthewild WRITEUP
poc
https://github.com/v3x0r/cve-2024-23738

Scores

CVSS v3 9.8
EPSS 0.1275
EPSS Percentile 94.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
postman/postman < 10.22
Published Jan 28, 2024
Tracked Since Feb 18, 2026