
CVE-2026-22018-Jenkins-Pipeline-Shared-Library-Code-Execution-via-Grab-
PoC for CVE-2026-22018, a critical Jenkins Pipeline Shared Library RCE via Groovy @Grab, demonstrating supply-chain code injection and mitigation…

PoC for CVE-2026-22018, a critical Jenkins Pipeline Shared Library RCE via Groovy @Grab, demonstrating supply-chain code injection and mitigation…

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

Proof-of-concept exploit for CVE-2024-32002, a Git submodule vulnerability enabling arbitrary code execution via crafted repositories and symlinks.

cve-2020-27955

PoC for CVE-2026-4660: arbitrary file read via git checkout in hashicorp/go-getter

Exploit for CVE-2026-33017, an unauthenticated RCE in Langflow 1.8.1 via the build_public_tmp endpoint, enabling Python code injection through…

Proof-of-concept exploit for CVE-2026-44590, a command injection in Sherlock's GitHub Actions workflow enabling RCE and GITHUB_TOKEN exfiltration via…

PoC for CVE-2026-7669: SGLang silent trust_remote_code override -> RCE

Advisory for textract ⌯⌲ 15 000 weekly downloads

CVE-2020-8809 and CVE-2020-8810

Exploit for remote command execution in Golang go get command.

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

Proof-of-concept exploit for CVE-2024-5082, a remote code execution vulnerability in Sonatype Nexus Repository Manager 2 via crafted Maven artifacts…

CocoaPods RCE Vulnerability CVE-2024-38366

CVE-2025-47273 — setuptools path traversal PoC

Detailed disclosure of CVE-2025-68664, a critical deserialization vulnerability in LangChain core allowing secret exfiltration and potential RCE via…

Proof-of-concept demonstrating arbitrary code execution in Orval via malicious OpenAPI fields, with setup, exploit steps, and remediation guidance.