
GitHacker
🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.

🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.

Persistent XSS in Typemill CMS: the Markdown parser lets javascript: URIs through unfiltered. Writeup + PoC.


Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field

PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.

CVE-2026-54597 - Authenticated Time-Based Blind SQL Injection in ITFlow

CVE-2026-54596 - Authenticated SQL Injection via recurring_invoice_frequency Parameter Enables Full Database Exfiltration


Gitea versions 1.1.0 → 1.12.5 allow authenticated users with "May create git hooks" permission to inject arbitrary shell commands into post-receive…


CVE-2022-39275 Setup and POC


Proof of concept for CVE-2022-36234

PoC for CVE-2022-23614 (Twig sort filter code execution/sandbox bypass)

CVE-2013-2028 python exploit

An information gathering tool to collect git commit emails in version control host services

Put the *.py files to test/functional folder of bitcoin sourcecode (commit: 4901c00792c1dabae4bb01e6373c9b1ed9ef3008)