CVE-2024-55963
MEDIUM
appsmith appsmith Improper Access Control
Record summary
CVE-2024-55963 has a selected CVSS score of 6.5 (medium); EIP currently links 2 catalogued exploits, 1 repository PoC, and 2 curated repository PoCs.
Description
An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is still within the Appsmith container, and the impact is limited to Appsmith's own server only, but there is a denial of service because it can be continually restarted. This is due to incorrect access control checks, which should check for super user permissions on the incoming request.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 15, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 27, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
appsmithBrowse appsmith / appsmith | VulnCheck | Version data not supplied | |
Proofs of concept
5Catalogued exploits
ExploitDBAppSmith 1.47 - Remote Code Execution (RCE)ExploitDB exploitby Nishanth GaddamNot analyzed1 file
MetasploitAppsmith RCEMetasploit exploitby Takahiro Yokoyama +1 moreNot analyzed1 file
Curated repository PoCs
GitHubCVE-2024-55963Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed4 files
GitHubCVE-2024-55965Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed3 files
Repository PoCs
GitHubsuperswan/CVE-2024-55963Repository PoCby superswanStars: 0Not analyzed2 files
References
1github.com
https://github.com/appsmithorg/appsmith/security/advisories/GHSA-6mc8-hw5c-7qqr