CVE-2023-52251
Executive Summary
CVE-2023-52251 exposes a remote code execution flaw in provectus kafka-ui (v0.4.0‑0.7.2) via the q parameter of /api/clusters/local/topics/{topic}/messages. The vulnerability allows attackers to run arbitrary code on the host. No patch has been released and the project has had no commits since 2024‑04‑08, leaving affected deployments exposed. The flaw is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 8.8 (HIGH) - Published: 2024-01-25T21:15:08.787 - Last Modified: 2026-09-08T19:17:43.673
Original Description: An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages. No fixed release is available; the project has had no commit since 2024-04-08.
"Myths which are believed in tend to become true."
— George Orwell