[CVE-2023-39631] Beyond the Bands: Exploiting TiTiler’s Expression Parser for Remote Code Execution
xbow.com | vulnerability | Critical | CVE-2023-39631 | #rce | #vulnerability-research | #python | #code-execution | #titiler | #expression-parser
Summary
A methodical study of TiTiler's expression parser that ends in arbitrary Python code execution on the server, with a bonus arbitrary file read saved for a follow-up post.
- CVSS
- 9.8
- Published
- Collected
Skip to content