
htb-labs-nexus
Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access,…

Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access,…

Docker-based lab environment for reproducing and exploiting CVE-2026-1357, with step-by-step setup and Burp Suite exploitation guidance.

Lab environment and proof-of-concept exploit for CVE-2026-1357, a WordPress plugin vulnerability, with Docker setup and automated exploitation…

Reproducible lab for CVE-2026-10053 (GitLab npm package-registry path traversal -> arbitrary file write as git). Vulnerable 19.2.1 vs patched 19.2.2,…

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

Dockerized vulnerable lab environment with a Python-based network monitor and dedicated exploit script, enabling hands-on exploitation, privilege…

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

Proof-of-concept exploit for CVE-2026-33718 demonstrating command injection in OpenHands' Git Diff Handler. Educational resource for vulnerability…

CVE-2020-13277 靶场: Gitlab 逻辑漏洞 - 任意用户越权访问私有仓库

CVE-2026-52813 (Gogs Path Traversal → Git Hooks RCE) defensive writeup: root-cause & patch analysis, Sigma/SIEM detection rules, IOCs, non-intrusive…

Proof of Concept - RCE Exploitation : Git submodules' names vulnerability - Ensimag November 2018

PoC for CVE-2017-8386 Git-Shell sandbox bypass vulnerability.

CVE-2021-22192 靶场: 未授权用户 RCE 漏洞

Proof-of-concept for CVE-2023-51385: demonstrates command injection via malicious git submodule URLs when cloning with --recurse-submodules,…

Exploit the dirtycow vulnerability to login as root

GIT vulnerability | Carriage Return and RCE on cloning

Lab environment and exploit script for CVE-2020-7246, a PHP code injection vulnerability in qdPM 9.1. Includes Docker setup and Python2-based…

Reproduction lab for CVE-2023-51385: command injection in OpenSSH ProxyCommand via malicious git submodule URLs. Step-by-step guide to verify the…