
CVE-2026-13714
Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

Proof-of-concept for Git LFS pointer poisoning, with Bash and Python scripts that create a malicious repository, simulate a rogue LFS server, and…

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying…

Python proof-of-concept for CVE-2025-8110, demonstrating arbitrary file write to RCE in Gogs via symlink and API, with educational lab usage.

Gogs RCE via argument injection in git rebase (CWE-88) — Python PoC. CVE-2026-52806

CVE-2026-25860 POC git

Gogs Symlink Traversal → RCE

GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and…

Gitea versions 1.1.0 → 1.12.5 allow authenticated users with "May create git hooks" permission to inject arbitrary shell commands into post-receive…

CVE-2025-65964 PoC - Malicious Git Hooks

Ronin is a Free and Open Source Ruby Toolkit for Security Research and Development. Ronin also allows for the rapid development and distribution of…

Detailed proof-of-concept and analysis of CVE-2021-28378, a stored XSS vulnerability in Gitea enabling arbitrary code injection, privilege…

Educational CTF demo demonstrating command execution via Git hooks by abusing core.hooksPath in automation workflows. Highlights local hook execution…

Exploit implementation for CVE-2024-10220 targeting a Git vulnerability. Provides a proof-of-concept shell script for testing and educational…

Proof-of-concept exploit for CVE-2025-48384, a Git submodule vulnerability leading to remote code execution through a malicious post-checkout hook.

PoC for CVE-2025-48384

Proof-of-concept exploit demonstrating remote code execution via a crafted git submodule during clone with --recurse-submodules. Targets…