
Proof-of-concept exploit for CVE-2026-27607, a missing post-policy validation in RustFS, demonstrating the vulnerability with a Node.js script and Docker-based vulnerable instance.
Proof of concept for CVE-2026-27607, published as GHSA-w5fh-f8xh-5x3p.
Needs Node.js and docker + compose.
npm cidocker compose up./exploit.js