
Gitea-template-sync-Path-Traversal-Privilege-Escalation-CVE-2026-38526-
PoC and write-up for the HackTheBox "Nexus" privilege escalation: root-run Gitea template-sync service vulnerable to path traversal via forged Git…

PoC and write-up for the HackTheBox "Nexus" privilege escalation: root-run Gitea template-sync service vulnerable to path traversal via forged Git…

Curated repository of Qubes OS security bulletins, canaries, PGP keys, and ISO digests, with authenticated verification via git tags and detached…

Docker-based lab environment for reproducing and exploiting CVE-2026-1357, with step-by-step setup and Burp Suite exploitation guidance.

Lab environment and proof-of-concept exploit for CVE-2026-1357, a WordPress plugin vulnerability, with Docker setup and automated exploitation…

Reproducible lab for CVE-2026-10053 (GitLab npm package-registry path traversal -> arbitrary file write as git). Vulnerable 19.2.1 vs patched 19.2.2,…

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

Local proof-of-concept for CVE-2026-71557 demonstrating path traversal in go-git filesystem reference storage, including exploit logic and…

Demonstrates command injection via unsanitized Git URLs in CI/CD pipelines, including a vulnerable build script and exploit example for a critical…

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

Proof-of-concept exploit for CVE-2026-33718 demonstrating command injection in OpenHands' Git Diff Handler. Educational resource for vulnerability…

Proof of Concept for CVE-2024-32002: Git submodule path injection vulnerability.

PoC for CVE-2017-8386 Git-Shell sandbox bypass vulnerability.

PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.

Test repository for verifying Git's CVE-2017-1000117 vulnerability and upgrading Git versions. Clone with --recursive to check safety.

Proof-of-concept for CVE-2023-51385: demonstrates command injection via malicious git submodule URLs when cloning with --recurse-submodules,…

Proof-of-concept exploit for CVE-2024-7703, a Stored XSS vulnerability in the ARMember WordPress plugin via malicious SVG file uploads by…

Automated SQL injection exploit for CVE-2024-6043 targeting SourceCodester Best House Rental Management System. Detects vulnerable endpoint and…