
CVE-2017-1000117
Proof-of-concept exploit for CVE-2017-1000117, a critical remote code execution vulnerability in Git. Includes Go and shell-based PoCs for testing…

Proof-of-concept exploit for CVE-2017-1000117, a critical remote code execution vulnerability in Git. Includes Go and shell-based PoCs for testing…

Proof of concept for the recent CVE-2026-25232 which is a priv esc vulnerability present in Gogs.

Local reproduction environment for CVE-2024-32002 Git RCE exploit using Gitea, with custom payload injection via post-checkout hooks and submodule…

Exploit for CVE-2020-27955, a Git LFS remote code execution vulnerability, with a .bat/powershell payload targeting Windows Git clients.

Single-script exploit for CVE-2026-44881 that chains .git credential leakage, Portainer Git-symlink injection, arbitrary host file read, and SSH…

PoC for CVE-2026-4660: arbitrary file read via git checkout in hashicorp/go-getter

Go-based exploit for CVE-2020-27955, achieving remote code execution via Git LFS on Windows across multiple development tools including Git, VS Code,…

Batch script exploit for CVE-2020-27955, achieving remote code execution via Git LFS on Windows. Targets git, GitHub CLI, VS Code, and other Git…

Batch and PowerShell exploit for CVE-2020-27955, a Git-LFS remote code execution vulnerability affecting Git, GitHub Desktop, VS Code, and other…

CVE-2023-23752 Data Extractor

Lab environment and proof-of-concept exploit for CVE-2026-1357, a WordPress plugin vulnerability, with Docker setup and automated exploitation…

Exploit for CVE-2018-18925: Remote Code Execution in Gogs via directory traversal in session handling, enabling session bypass and administrator…

Windows RCE exploit for CVE-2020-27955 targeting git-lfs, affecting GitHub Desktop, VS Code, and other Git clients via crafted .bat/powershell…

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

Local proof-of-concept for CVE-2026-71557 demonstrating path traversal in go-git filesystem reference storage, including exploit logic and…

A script to exploit CVE-2020-14144 - GiTea authenticated Remote Code Execution using git hooks

Git-lfs RCE exploit CVE-2020-27955 - tested on Windows on: git, gh cli, GitHub Desktop, Visual Studio, SourceTree etc.

CVE-2022-29221 Proof of Concept Code - Smarty RCE