
Malicious Register Directive Code Injection Exploit
This repository provides a production-ready exploit for CVE-2026-65660 (Improper Control of Generation of Code, CWE-94) in Microsoft SharePoint Server. The vulnerability stems from unescaped quote injection into Register directives, bypassing SafeControls validation and enabling arbitrary code execution via XamlServices.Parse() deserialization.
The exploit allows an authorized low-privilege user to inject malicious directives, achieve remote code execution, deploy a persistent in-memory webshell, escalate privileges via SharePoint service context, perform lateral movement in the farm, establish C2, exfiltrate sensitive documents/data, and disrupt collaboration services.
Contact us for private access: [email protected]
pip install requests
python exploit.py [options]
Report & PoC: ShadowForge Cyber