
PoCs & write-ups for CVEs I reported (coordinated disclosure; published + patched only)
Proof-of-concept code and technical write-ups for vulnerabilities I discovered and reported through coordinated disclosure. Every entry here is already public: the vendor advisory is published and a fixed release is available. Nothing under embargo or in draft is included.
The PoCs are verification harnesses, not weaponized exploits: each runs against a local, self-owned instance and proves the defect with a benign sentinel (a marker file, a seeded "secret" record, a policy-evaluation assertion). None of them target third-party systems, and none perform any destructive or persistent action.
— Pig-Tail · Offensive Security Engineer & Vulnerability Researcher · [email protected]
| CVE / Advisory | Project | Class (CWE) | Severity | PoC |
|---|---|---|---|---|
| GHSA-f5m5-jfmq-ghpx | SteeltoeOSS/NetCoreToolService | Unauthenticated RCE via argument injection into 'dotnet new' (CWE-88) | Critical | ✅ runnable |
| CVE-2026-77312 | flyto-core | Arbitrary file write via unguarded data./file. modules (in (CWE-22) | Critical | ✅ runnable |
| GHSA-7833-fr7j-v32q | GitPython | Arbitrary local file content disclosure via [include] direct (CWE-73/CWE-200) | High | ✅ runnable |
| GHSA-284h-m62q-gf8w | GitPython | Dormant multi-line git-config values are corrupted into live (CWE-88/CWE-94) | High | ✅ runnable |
| GHSA-8mcc-hrx5-hvxc | GitPython | clone_from()/clone() omit --separate-git-dir from unsafe_git (CWE-22/CWE-73) | High | ✅ runnable |
| CVE-2026-62263 | OpenAM | OpenAM WebAuthn Java deserialization RCE via ObjectInputFilt (CWE-502) | High | 📄 write-up |
| CVE-2026-53626 | glpi | Arbitrary document read (CWE-639/CWE-862) | High | 📄 write-up |
| CVE-2026-75606 | egroupware | Authenticated SQL injection via col_filter string-key in Base (CWE-89) | High | ✅ runnable |
| CVE-2026-93537 | fleet | Path traversal in Helm valuesFiles reads outside the bundle (CWE-22/CWE-200) | High | 📄 write-up |
| CVE-2026-93538 | fleet | Cross-tenant BundleDeployment/Secret disclosure via spoofed (CWE-290/CWE-639/CWE-863) | High | 📄 write-up |
| CVE-2026-49285 | glpi-agent | OS Command Injection in GLPI Agent ToolBox Results export vi (CWE-78) | High | 📄 write-up |
| CVE-2026-52764 | glpi-agent | MSSQL inventory module executes OS commands with unsanitized (CWE-78) | High | 📄 write-up |
| CVE-2026-45621 | glpi-agent | MongoDB inventory module allows JavaScript injection via une (CWE-94/CWE-116) | High | 📄 write-up |
| CVE-2026-46615 | glpi-agent | Database inventory modules execute OS commands with unsaniti (CWE-78) | High | 📄 write-up |
| CVE-2026-40936 | glpi-agent | ToolBox plugin can allow unauthenticated path traversal lead (CWE-22/CWE-73) | High | 📄 write-up |
| CVE-2026-48730 | glpi-inventory-plugin | Reflected XSS (CWE-79) | High | 📄 write-up |
| CVE-2026-75594 | kirby | Access to image files and limited access to JSON files outsi (CWE-22) | High | 📄 write-up |
| CVE-2026-77437 | kiwitcms | ORM lookup-injection in RPC *.filter methods leaks bug-track (CWE-943/CWE-200) | High | ✅ runnable |
| CVE-2026-77435 | kiwitcms | Authenticated SSRF via Bug.details API method (CWE-918/CWE-697) | High | ✅ runnable |
| CVE-2026-58229 | mint | Unbounded HTTP/1 response-header and chunked-trailer accumul (CWE-770) | High | ✅ runnable |
| CVE-2026-61699 | nebula-mesh | Certificate revocation is never enforced at the mesh: nebula (CWE-299/CWE-672) | High | 📄 write-up |
| CVE-2026-63202 | netty-incubator-codec-ohttp | BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via inf (CWE-400/CWE-835) | High | ✅ runnable |
| GHSA-p6gq-j5cr-w38f | nodemailer | Message-level raw option bypasses disableFileAccess/disableU (CWE-73/CWE-918) | High | ✅ runnable |
| CVE-2026-71315 | nuxt | Nuxt route rules silently dropped for mixed-case paths, bypa (CWE-178/CWE-863) | High | ✅ runnable |
| CVE-2026-62375 | opendj | OpenDJ Unbounded VLV offset array allocation → memory-exhaus (CWE-190/CWE-770/CWE-789) | High | 📄 write-up |
| CVE-2026-62366 | opendj | OpenDJ Unauthenticated stack exhaustion when decoding an LDA (CWE-400/CWE-674) | High | 📄 write-up |
| GHSA-r9mf-88r7-g6j9 | probo | Account takeover via OIDC login: the continue redirect hands (CWE-384/CWE-601) | High | ✅ runnable |
| CVE-2026-76079 | probo | Vertical privilege escalation: an organization ADMIN can min (CWE-269/CWE-863) | High | ✅ runnable |
| GHSA-fj3w-533r-fvf6 | python-statemachine | SCXML reads arbitrary local files when (CWE-22/CWE-200) | High | ✅ runnable |
| GHSA-r7hw-jx6r-756g | saml2 | Incomplete fix of CVE-2026-49283: unsigned embedded Response (CWE-287/CWE-347) | High | ✅ runnable |
| CVE-2026-62989 | shopper | Missing authorization on product variant DeleteAction/Delete (CWE-285/CWE-862) | High | 📄 write-up |
| CVE-2026-86043 | skipper | OPA body-authz bypass: truncated_body mitigation fails ope (CWE-863) | High | ✅ runnable |
| CVE-2026-54697 | cbssh | Excessive allocation and integer overflow in DER private-key (CWE-190/CWE-789) | Medium | 📄 write-up |