OSGeo GeoServer GeoTools Eval Injection Vulnerability

OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unauthenticated attackers to conduct remote code execution via specially crafted input.

Published 14 Sep 2026Updated 14 Sep 202625 sources
CVSS 0.0 PoC CANDIDATE△ CISA KEV

What happened

OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unauthenticated attackers to conduct remote code execution via specially crafted input.

Affected versions

GeoServer: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
PoC-in-GitHub · bigb0x/CVE-2024-36401POC for CVE-2024-36401. This POC will attempt to establish a reverse shell from the vlun targets.★ 35bigb0x2024-07-04CandidatePoC-in-GitHub · Niuwoo/CVE-2024-36401POC★ 4Niuwoo2024-07-05CandidatePoC-in-GitHub · RevoltSecurities/CVE-2024-36401Exploiter a Vulnerability detection and Exploitation tool for GeoServer Unauthenticated Remote Code Execution CVE-2024-36401.★ 1RevoltSecurities2024-07-05CandidatePoC-in-GitHub · Mr-xn/CVE-2024-36401Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions with multies ways to exploit★ 56Mr-xn2024-07-06CandidatePoC-in-GitHub · jakabakos/CVE-2024-36401-GeoServer-RCE★ 0jakabakos2024-07-12CandidatePoC-in-GitHub · ahisec/geoserver-geoserver CVE-2024-36401漏洞利用工具★ 45ahisec2024-07-17CandidatePoC-in-GitHub · Chocapikk/CVE-2024-36401GeoServer Remote Code Execution★ 89Chocapikk2024-07-30CandidatePoC-in-GitHub · y1s4s/CVE-2024-36401-PoC★ 0y1s4s2024-08-01CandidatePoC-in-GitHub · justin-p/geoexplorerMass scanner for CVE-2024-36401★ 4justin-p2024-08-27CandidatePoC-in-GitHub · daniellowrie/CVE-2024-36401-PoCProof-of-Concept Exploit for CVE-2024-36401 GeoServer 2.25.1★ 3daniellowrie2024-09-13CandidatePoC-in-GitHub · punitdarji/GeoServer-CVE-2024-36401GeoServer CVE-2024-36401: Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions★ 1punitdarji2024-09-28CandidatePoC-in-GitHub · kkhackz0013/CVE-2024-36401★ 0kkhackz00132024-10-14CandidatePoC-in-GitHub · 0x0d3ad/CVE-2024-36401CVE-2024-36401 (GeoServer Remote Code Execution)★ 20x0d3ad2024-11-27CandidatePoC-in-GitHub · funnyDog896/CVE-2024-36401-WoodpeckerPluginCVE-2024-36401-GeoServer Property 表达式注入 Rce woodpecker-framework 插件★ 0funnyDog8962024-11-28CandidatePoC-in-GitHub · whitebear-ch/GeoServerExploitGeoServer(CVE-2024-36401/CVE-2024-36404)漏洞利用工具★ 122whitebear-ch2025-01-07CandidatePoC-in-GitHub · bmth666/GeoServer-Tools-CVE-2024-36401CVE-2024-36401 图形化利用工具,支持各个JDK版本利用以及回显、内存马实现★ 43bmth6662025-04-11CandidatePoC-in-GitHub · amoy6228/CVE-2024-36401_Geoserver_RCE_POC本脚本是针对 GeoServer 的远程代码执行漏洞(CVE-2024-36401)开发的 PoC(Proof of Concept)探测工具。该漏洞允许攻击者通过构造特定请求,在目标服务器上执行任意命令。★ 2amoy62282025-04-30CandidatePoC-in-GitHub · URJACK2025/CVE-2024-36401An Python Exp For "GeoServer"★ 2URJACK20252025-10-04CandidatePoC-in-GitHub · mantanhacker/CVE-2024-36401-MASSGeoserver RCE★ 0mantanhacker2025-12-05CandidatePoC-in-GitHub · Delt-A/CVE-2024-36401-poc★ 0Delt-A2026-05-30CandidatePoC-in-GitHub · DanieleGiovanardi2408/cve-2024-36401-geoserver-rce★ 0DanieleGiovanardi24082026-06-03CandidatePoC-in-GitHub · keelanbrady1011/CVE-2024-36401Remix of Chokapikk's CVE-2024-36401 to allow webshell-like behaviour on limited environments★ 0keelanbrady10112026-07-07CandidatePoC-in-GitHub · raniaemran/cve-2024-36401-security-simulator★ 0raniaemran2026-09-15Candidate