On this page

Atomicorp WAF Rule 345240

Rule Summary

  • Rule ID: 345240
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: Node.js RCE primitive detected in request
  • Observed CWEs: CWE-20 (2), CWE-74 (1), CWE-77 (3), CWE-78 (2), CWE-89 (1), CWE-94 (6), CWE-200 (1), CWE-352 (1), CWE-502 (2), CWE-913 (2), CWE-942 (1), CWE-1188 (1)
  • Revision: 2
  • Rule severity: Critical
  • Phase: 2 (request body)
  • Request surfaces: Request body, Request argument names, Request arguments, JSON request data, SOAP request data, XML request data
  • Rule action: deny
  • HTTP status: 403
  • Public tags: attack-rce, language-nodejs
  • Logging: log, auditlog

Description

This rule detects behavior identified by its current alert as “Node.js RCE primitive detected in request” in the request body, request argument names, request arguments, JSON request data, SOAP request data, XML request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2025-55182React Server Components - Remote Code Executionreact10.0 (v3.1)Critical
CVE-2025-59528Flowise - Remote Code Executionflowise10.0 (v3.1)Critical
CVE-2026-47668DbGate - Remote Code Execution via Anonymous JWTdbgate10.0 (v3.1)Critical
CVE-2019-10758mongo-express Remote Code Executionmongo-express9.9 (v3.1)Critical
CVE-2026-34156NocoBase - VM Sandbox Escape to Remote Code Executionnocobase9.9 (v3.1)Critical
CVE-2020-24391Mongo-Express - Remote Code Executionmongo-express9.8 (v3.1)Critical
CVE-2022-29078Node.js Embedded JavaScript 3.1.6 - Template Injectionejs9.8 (v3.1)Critical
CVE-2023-29827Embedded JavaScript(EJS) 3.1.6 - Template Injectionejs9.8 (v3.1)Critical
CVE-2023-33831FUXA - Unauthenticated Remote Code Executionfuxa9.8 (v3.1)Critical
CVE-2026-34449SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injectionsiyuan9.6 (v3.1)Critical
CVE-2025-54782NestJS DevTools Integration - Remote Code Executiondevtools-integration9.4 (v4.0)Critical
CVE-2026-46442Flowise < 3.1.2 - node-custom-function Unauthorized RCEflowise9.4 (v4.0)Critical
CVE-2026-47670DbGate - Remote Code Execution via Dynamic Import Bypassdbgate9.4 (v4.0)Critical
CVE-2024-53900Mongoose < 8.8.3 - Remote Code Executionmongoose9.1 (v3.1)Critical
CVE-2025-1302JSONPath Plus < 10.3.0 - Remote Code Executionjsonpath-plus8.9 (v4.0)High
CVE-2021-32819Nodejs Squirrelly - Remote Code Executionsquirrelly8.8 (v3.1)High
CVE-2025-68613n8n - Remote Code Execution via Expression Injectionn8n8.8 (v3.1)High
CVE-2025-8266ChanCMS <= 3.1. - Remote Code Executionchancms2.1 (v4.0)Low

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-20CVE-2026-47668 , CVE-2025-8266
CWE-74CVE-2023-29827
CWE-77CVE-2023-33831 , CVE-2025-54782 , CVE-2026-47670
CWE-78CVE-2025-54782 , CVE-2026-47670
CWE-89CVE-2024-53900
CWE-94CVE-2025-59528 , CVE-2026-47668 , CVE-2019-10758 , CVE-2022-29078 , CVE-2026-46442 , CVE-2025-1302
CWE-200CVE-2021-32819
CWE-352CVE-2025-54782
CWE-502CVE-2025-55182 , CVE-2025-8266
CWE-913CVE-2026-34156 , CVE-2025-68613
CWE-942CVE-2026-34449
CWE-1188CVE-2026-47668