
CVE-2024-32002
A proof of concept for the git vulnerability CVE-2024-32002

A proof of concept for the git vulnerability CVE-2024-32002

Proof-of-concept exploit for CVE-2026-6951, a simple-git --config filter bypass enabling RCE via the Git ext protocol, with a Docker lab and reverse…

Fork of gogs/gogs for reachability benchmark testing (CVE-2024-45337)

Proof-of-concept for Git LFS pointer poisoning, with Bash and Python scripts that create a malicious repository, simulate a rogue LFS server, and…

remote code exec for git

vulnerabilities, CVE-2022-41903, and CVE-2022-23521, that affect versions 2.39 and older. Git for Windows was also patched to address an additional,…

for git v2.7.4

Proof-of-concept exploit for CVE-2017-1000117, a remote code execution vulnerability in git clients prior to v2.14.1, demonstrating recursive clone…

Original standalone Proof-of-Concept exploit for CVE-2023-23946 (Git path traversal via crafted patches in git-apply).

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

Authenticated remote code execution exploit for Jenkins Git Client Plugin 2.8.2 via Jackson deserialization vulnerability (CVE-2019-10392).

RCE exploit for CVE-2020-27955 targeting Git LFS on Windows, with .bat and PowerShell payloads for testing Git, GitHub CLI, VS Code, and other tools.

Proof-of-concept exploit for CVE-2021-21300, demonstrating exploitation of a Git vulnerability for remote code execution.

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.

Proof of Concept for CVE-2024-32002: Git submodule path injection vulnerability.

Proof-of-concept exploit for CVE-2017-1000117 (Git SSH command injection) that writes command output to a web-accessible file. Part of VulApps…

Local reproduction environment for CVE-2024-32002 Git RCE exploit using Gitea, with custom payload injection via post-checkout hooks and submodule…