Record summary

CVE-2024-55963 has a selected CVSS score of 6.5 (medium); EIP currently links 2 catalogued exploits, 1 repository PoC, and 2 curated repository PoCs.

Description

An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is still within the Appsmith container, and the impact is limited to Appsmith's own server only, but there is a denial of service because it can be continually restarted. This is due to incorrect access control checks, which should check for super user permissions on the incoming request.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 15, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
2
Repository PoCs
1
Curated repository PoCs
2

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 27, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

5

Catalogued exploits

ExploitDBAppSmith 1.47 - Remote Code Execution (RCE)ExploitDB exploitby Nishanth GaddamNot analyzed1 file
ExploitDB

PoC details
MetasploitAppsmith RCEMetasploit exploitby Takahiro Yokoyama +1 moreNot analyzed1 file

Ruby · linked to 2 vulnerabilities

Metasploit

PoC details

Curated repository PoCs

GitHubCVE-2024-55963Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed4 files

Python · 363.8 KiB

GitHub

PoC details
GitHubCVE-2024-55965Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed3 files

Python · 2.1 MiB · linked to 2 vulnerabilities

GitHub

PoC details

Repository PoCs

GitHubsuperswan/CVE-2024-55963Repository PoCby superswanStars: 0Not analyzed2 files

12.9 KiB

GitHub

PoC details

References

1