
CVE-2021-21300
Exploit script for CVE-2021-21300, a Git vulnerability allowing arbitrary code execution. Provides proof-of-concept code for security testing and…

Exploit script for CVE-2021-21300, a Git vulnerability allowing arbitrary code execution. Provides proof-of-concept code for security testing and…

Proof-of-concept exploit for CVE-2024-32002, a Git submodule vulnerability that enables remote code execution on Linux through crafted repositories.

Proof-of-concept exploit for CVE-2024-32002, a Git remote code execution vulnerability, demonstrating exploitation techniques for security research.

CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

GitBackdorizer (bad name, I know!) Is a proof of concept from Ulisses Castro's talk - 50 ton of backdoors…

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Windows Remote Desktop Services Vulnerability Allows Remote Code Execution

Proof-of-concept for Git LFS pointer poisoning, with Bash and Python scripts that create a malicious repository, simulate a rogue LFS server, and…

A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying…

OfensivePipeline allows you to download and build C# tools, applying certain modifications in order to improve their evasion for Red Team exercises.

Relays NegoEx/PKU2U Kerberos authentication to arbitrary targets, enabling credentialless authentication, command execution, SMB hash dumping, and…

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

Automated PoC exploit for CVE-2025-68937 — Gitea/Forgejo Template Symlink RCE. Any authenticated user can get a shell as the git service user.

CVE-2026-45033 PoC for Claude Code, not Github Copilot. Worked for Haiku 4.5.

An automated SMB relay exploitation script.

Exploit for CVE-2024-44625 in Gogs 0.13.0, achieving remote code execution via symlink-follow to create a git hook, with reverse and bind shell modes.

GitPwnd is a network penetration tool that lets you use a git repo for command and control of compromised machines

Automated Exploit Toolkit for CVE-2015-6095 and CVE-2016-0049