
CVE-2026-60004
CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)


Evade EDR's the simple way, by not touching any of the API's they hook.

proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more…

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution

CVE-2024-10220 Test repo

Leverage WindowsApp createdump tool to obtain an lsass dump


A submodule for exploiting CVE-2024-32002 vulnerability.

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

A proof of concept for abusing exception handlers to hook and bypass user mode EDR hooks.

Git Web Hook Tunnel for C2

Agent-based tool that collects OS, hardware, file, and hook data from internet-connected sandboxes via HTTPS exfiltration, aiding Red Team artifact…


Hook PasswordChangeNotify