
cve-2024-32002-poc-aw
A POC for CVE-2024-32002 demonstrating arbitrary write into the .git directory.

A POC for CVE-2024-32002 demonstrating arbitrary write into the .git directory.

Curated inventory of cybersecurity tools and resources covering penetration testing, forensics, OSINT, web security, malware analysis, cryptography,…

PoC and write-up for the HackTheBox "Nexus" privilege escalation: root-run Gitea template-sync service vulnerable to path traversal via forged Git…

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

Educational CTF demo demonstrating command execution via Git hooks by abusing core.hooksPath in automation workflows. Highlights local hook execution…

Reproduction script for CVE-2025-48384, a git clone RCE via carriage return in submodule paths, demonstrating the vulnerability and providing a local…

Docker-based lab for exploring and reproducing the Next.js CVE-2025-29927 middleware authorization bypass vulnerability. Includes vulnerable app,…

Docker-based lab environment for reproducing and exploiting CVE-2026-1357, with step-by-step setup and Burp Suite exploitation guidance.

Reproducible lab for CVE-2026-10053 (GitLab npm package-registry path traversal -> arbitrary file write as git). Vulnerable 19.2.1 vs patched 19.2.2,…

Proof-of-concept exploit for CVE-2025-48384, demonstrating remote code execution via a crafted git clone operation on vulnerable Git versions.

Lab environment and proof-of-concept exploit for CVE-2026-1357, a WordPress plugin vulnerability, with Docker setup and automated exploitation…

Local reproduction environment for CVE-2024-32002 Git RCE exploit using Gitea, with custom payload injection via post-checkout hooks and submodule…

Proof-of-concept exploit for CVE-2017-1000117 (Git clone command injection) targeting SSH, designed for vulnerability testing and educational lab…

Proof-of-concept exploit for CVE-2026-33718 demonstrating command injection in OpenHands' Git Diff Handler. Educational resource for vulnerability…

PoC for CVE-2017-8386 Git-Shell sandbox bypass vulnerability.

Proof-of-concept for CVE-2023-51385: demonstrates command injection via malicious git submodule URLs when cloning with --recurse-submodules,…

Proof-of-concept exploit for CVE-2017-1000117, demonstrating command injection via git clone to write arbitrary output to a web directory.