
CVE-2026-85706-PoC-Toolkit
Python toolkit for CVE-2026-85706 GitLab unauth file read: weaponized exploit with loot, shell, mass scan, plus non-intrusive SafeChecker audit and…

Python toolkit for CVE-2026-85706 GitLab unauth file read: weaponized exploit with loot, shell, mass scan, plus non-intrusive SafeChecker audit and…

Perl PoC exploiting CVE-2026-85706, an unauthenticated GitLab path traversal enabling arbitrary file read, with bulk scanning and credential…

CVE-2026-85706 · GitLab CE/EE unauthenticated file read · research PoC with oracle mode, fd enumeration, and tiered loot targeting

Proof-of-concept exploit for CVE-2026-19478, an unauthenticated GraphQL injection in GitLab CE/EE allowing arbitrary method invocation and project…

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Fully automated Spring4Shell (CVE-2022-22965) + GitLab RCE framework

CVE-2024-0402 exploit for GitLab Workspaces using a malicious Devfile Registry with path-traversal archive to overwrite authorized_keys and gain SSH…

Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit

Pre-authentication remote code execution exploit targeting GitLab CE/EE via ExifTool DjVu parsing. Uploads a crafted image to trigger RCE on…

Proof-of-concept exploit for CVE-2023-7028, automating GitLab account takeover via password reset email manipulation. Includes temp-mail integration…

Exploit tool targeting CVE-2023-7028 in GitLab, enabling account takeover through password reset vulnerability.

This repository presents a proof-of-concept of CVE-2023-7028

CVE-2023-7028

A simple bash script that exploits CVE-2021-22205 against vulnerable instances of gitlab

GitLab CVE-2023-2825 PoC. This PoC leverages a path traversal vulnerability to retrieve the /etc/passwd file from a system running GitLab 16.0.0.

Exploits GitLab authenticated RCE vulnerability known as CVE-2022-2884.

Authenticated Remote Command Execution in Gitlab via GitHub import

wo ee cve-2022-2185 gitlab authenticated rce