On this page
Atomicorp WAF Rule 345240
Rule Summary
- Rule ID: 345240
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Node.js RCE primitive detected in request
- Observed CWEs: CWE-20 (2), CWE-74 (1), CWE-77 (3), CWE-78 (2), CWE-89 (1), CWE-94 (6), CWE-200 (1), CWE-352 (1), CWE-502 (2), CWE-913 (2), CWE-942 (1), CWE-1188 (1)
- Revision: 2
- Rule severity: Critical
- Phase: 2 (request body)
- Request surfaces: Request body, Request argument names, Request arguments, JSON request data, SOAP request data, XML request data
- Rule action: deny
- HTTP status: 403
- Public tags: attack-rce, language-nodejs
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Node.js RCE primitive detected in request” in the request body, request argument names, request arguments, JSON request data, SOAP request data, XML request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2025-55182 | React Server Components - Remote Code Execution | react | 10.0 (v3.1) | Critical |
| CVE-2025-59528 | Flowise - Remote Code Execution | flowise | 10.0 (v3.1) | Critical |
| CVE-2026-47668 | DbGate - Remote Code Execution via Anonymous JWT | dbgate | 10.0 (v3.1) | Critical |
| CVE-2019-10758 | mongo-express Remote Code Execution | mongo-express | 9.9 (v3.1) | Critical |
| CVE-2026-34156 | NocoBase - VM Sandbox Escape to Remote Code Execution | nocobase | 9.9 (v3.1) | Critical |
| CVE-2020-24391 | Mongo-Express - Remote Code Execution | mongo-express | 9.8 (v3.1) | Critical |
| CVE-2022-29078 | Node.js Embedded JavaScript 3.1.6 - Template Injection | ejs | 9.8 (v3.1) | Critical |
| CVE-2023-29827 | Embedded JavaScript(EJS) 3.1.6 - Template Injection | ejs | 9.8 (v3.1) | Critical |
| CVE-2023-33831 | FUXA - Unauthenticated Remote Code Execution | fuxa | 9.8 (v3.1) | Critical |
| CVE-2026-34449 | SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection | siyuan | 9.6 (v3.1) | Critical |
| CVE-2025-54782 | NestJS DevTools Integration - Remote Code Execution | devtools-integration | 9.4 (v4.0) | Critical |
| CVE-2026-46442 | Flowise < 3.1.2 - node-custom-function Unauthorized RCE | flowise | 9.4 (v4.0) | Critical |
| CVE-2026-47670 | DbGate - Remote Code Execution via Dynamic Import Bypass | dbgate | 9.4 (v4.0) | Critical |
| CVE-2024-53900 | Mongoose < 8.8.3 - Remote Code Execution | mongoose | 9.1 (v3.1) | Critical |
| CVE-2025-1302 | JSONPath Plus < 10.3.0 - Remote Code Execution | jsonpath-plus | 8.9 (v4.0) | High |
| CVE-2021-32819 | Nodejs Squirrelly - Remote Code Execution | squirrelly | 8.8 (v3.1) | High |
| CVE-2025-68613 | n8n - Remote Code Execution via Expression Injection | n8n | 8.8 (v3.1) | High |
| CVE-2025-8266 | ChanCMS <= 3.1. - Remote Code Execution | chancms | 2.1 (v4.0) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.