CHAINLINE

CHAINLINECHAINLINE

Description

CHAINLINE is a Python webshell backdoor that is embedded in a Ivanti Connect Secure Python package that enables arbitrary command execution./nCHAINLINE was identified in the CAV Python package in the following path: /home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/resources/health.py. This is the same Python package modified to support the WIREFIRE web shell./nUnlike WIREFIRE, which modifies an existing file, CHAINLINE creates a new file called health.py, which is not a legitimate filename in the CAV Python package. The existence of this filename or an associated compiled Python cache file may indicate the presence of CHAINLINE./nUNC5221 registered a new API resource path to support the access of CHAINLINE at the REST endpoint /api/v1/cav/client/health. This was accomplished by importing the maliciously created Health API resource and then calling the add_resource() class method on the FLASK-RESTful Api object within /home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/__init__.py.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
FRAMESTING
CVE
CVE-2026-44211
CVE
Commvault Command Center Path Traversal Vulnerability
CVE
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
CVE
CVE-2026-30312
CVE
CVE-2026-7466
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.