CVE-2024-51358

CRITICAL

Heimdall 2.6.1 - Remote Code Execution via Add New Application

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-51358. PoCs published by Kov404.

AI-analyzed exploit summary This repository contains a writeup describing CVE-2024-51358, an SSRF vulnerability in Heimdall version 2.6.1. The vulnerability allows remote attackers to perform HTTP requests via the Add Application feature.

Description

An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application.

Exploits (1)

nomisec WRITEUP
by Kov404 · poc
https://github.com/Kov404/CVE-2024-51358

This repository contains a writeup describing CVE-2024-51358, an SSRF vulnerability in Heimdall version 2.6.1. The vulnerability allows remote attackers to perform HTTP requests via the Add Application feature.

Classification
Writeup 90%
Attack Type
Ssrf
Complexity
Trivial
Reliability
Theoretical
Target: Heimdall version 2.6.1
No auth needed
Prerequisites: Access to the Add Application feature in Heimdall
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0092
EPSS Percentile 55.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-918
Status published
Published Nov 05, 2024
Tracked Since Feb 18, 2026