Skip to content

Image: exploit-db.com · rights & removal

Executive Summary

A vulnerability in TigerGraph Community Edition 4.2.4 allows for a remote code execution chain by leveraging default configurations and specific query capabilities. Initial access is gained through default credentials (tigergraph:tigergraph) on the GUI port, which provides session cookies. This session is used to execute a malicious GSQL command that abuses file write privileges via a specific query, leading to an arbitrary file write primitive without requiring further authentication for subsequent steps. The process involves generating an SSH public key and writing it to the system's `authorizedkeys` file, ultimately enabling remote command execution on the database host as the `tigergraph` user. This chain relies on sequential exploitation of weak default security settings across the GUI, REST++, and SSH services.

Facts Only

* TigerGraph Community Edition 4.2.4 permits a remote code-execution chain against the database host.
* The GUI administration port (14240) accepts default credentials: tigergraph:tigergraph.
* A specific GSQL query, `CREATE QUERY (FILE f, STRING c) { PRINT c TOCSV f; }`, allows unrestricted write to the FILE parameter without path validation.
* REST++ on port 9000 runs with `RESTPP.Factory.EnableAuth = False`, allowing unauthenticated file writes via a GET request.
* An unauthenticated GET request to `/query//?f=&c=` can write an arbitrary file in the context of this mechanism.
* The attacker can plant an SSH public key into `/home/tigergraph/.ssh/authorizedkeys`.
* SSH daemon is started with `OpenSSH default PubkeyAuthentication=yes`.
* SSH logon as `tigergraph@` allows command execution.
* The resulting user identity for command execution is the `tigergraph` user (UID 1001), not root.

Full Take

The vulnerability chain exemplifies a failure across multiple layers of security—authentication, input validation, and service isolation—where exploiting one weakness permits escalation to full system control. The critical pattern involves chaining low-severity flaws: default credentials (CWE-798), insecure query execution (CWE-73), lack of authorization in REST++ (CWE-306), and trusting the SSH daemon configuration. This is a textbook example of how predictable defaults, when combined with application logic that trusts user-supplied data for file operations, can bridge disparate system boundaries. The emphasis on URL encoding for SSH keys reveals an awareness that even seemingly simple protocols require meticulous handling of character sets to prevent complete failure, which introduces complexity in the execution path itself. The implication is that security posture often relies not on the strength of individual components but on the integrity of their integration and assumed trust boundaries. What are the systemic failures in design that allow such disparate primitives to connect so seamlessly? What controls are missing at the architectural level to prevent file system manipulation from leaking into SSH credentials structures?

From the original · Exploit Database

Title: TigerGraph_Community_Edition 4.2.4 - arbitrary file write Author: 0day Rubbish Research Team Contact: disclosure@0day-rubbish.com Type: remote Platform: Linux TigerGraph Community Edition 4.2.4 -- default credentials + arbitrary file write -> SSH RCE Vulnerability summary: TigerGraph Community Edition 4.2.4 in its default configuration permits a remote code-execution chain against the…
Read the full story at exploit-db.com

Sentinel — Human

Confidence

This text reads like a detailed technical proof-of-concept or exploit write-up, exhibiting high domain specificity and procedural depth consistent with expert security research, likely human-authored.

Signals Detected
low severity: Moderate sentence length variance and specialized, precise technical terminology, typical of security disclosure writing.
low severity: Highly structured, procedural explanation of a vulnerability chain; lacks the overly smooth, balanced tone of general AI summaries.
low severity: Coherent flow mirroring a specific exploit methodology (Step 1 through Step 4); uses specific technical citations (CWEs) which implies deep domain knowledge, not generic LLM boilerplate.
medium severity: The complexity of the encoded instructions and interaction between disparate protocols (HTTP, REST++, SSH) suggests expert-level manual crafting, though some scaffolding might be AI-assisted.
Human Indicators
Specific, highly technical encoding notes regarding space handling in SSH keys, indicating practical, hands-on knowledge.
The detailed mapping of file operations to specific security flaws (CWE-798, CWE-73, CWE-306) is characteristic of deep security research.
The inclusion of Python script and explicit variable definitions suggests the author is demonstrating the precise execution path rather than just stating a result.
[webapps] TigerGraph_Community_Edition 4.2.4 | Huntaegis