Feed/GHSA-9gqx-53gp-c8g3
GHSA-9gqx-53gp-c8g3HIGHCVSS 7.3

Duplicate Advisory: uutils coreutils allows users to bypass the --preserve-root safety mechanism

Published Apr 22, 2026·Updated Jul 6, 2026

NVD Description

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-4c7q-4928-8445. This link is maintained to preserve external references. ### Original Description A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the target path is literally / and does not canonicalize the path. An attacker or accidental user can use path variants such as /../ or symbolic links to execute destructive recursive operations (e.g., chmod -R 000) on the entire root filesystem, leading to system-wide permission loss and potential complete system breakdown.

Affected Packages (1)

coreutilsCARGO
Fixed in 0.6.0

Public Exploits & PoCs100 found

PoC: TLPE

CVE-2026-49881, a logic issue in the InCallController class in Android 17's Telecom service that allows an unprivileged app to gain arbitrary code execution as UID 1000 system_server

11

PoC: cve-2026-85706

Exploit poc for CVE-2026-85706 an unauthenticated arbitrary file read on Gitlab CE-EE affecting versions: 18.7–19.1.7; 19.2.0–19.2.5; 19.3.0–19.3.1

4

PoC: CVE-2026-20805-PoC

🛡️ Official AI Security Tool module for CVE-2026-20805 (Desktop Window Manager / dwm.exe Information Disclosure & Memory Leak Diagnostic).

3

PoC: cve-2026-75650-magento-validation-lab

Docker lab for validating the CVE-2026-75650 Magento component-level PHP execution primitive and Adobe VULN-39341 patch.

2

PoC: CVE-2026-85706

GitLab CE/EE unauthenticated path traversal (CVE-2026-85706) - PoC

1

PoC: BLUE-WRITEUP-CVE-2017-0144

Conducted a complete security assessment of an unpatched Windows 7 target ("Blue") to demonstrate the impact of legacy service vulnerabilities in an enterprise environment

1

PoC: POC-AIOWPM-CVE-2026-19949

PoC funcional de CVE-2026-19949 (AIOWPM): SQLi de segundo orden no autenticada en All-in-One WP Migration <= 7.109 via regex de replace_table_values. Laboratorio Docker + payload derivado (leak de ai1wm_secret_key por REST anonima) + RCE con importacion anonima.

1

PoC: CVE-2025-38502-Linux-LPE

CVE-2025-38502 Linux LPE. BPF cgroup local storage OOB via tail calls. Affected kernels: 5.9–5.15.191, 5.16–6.1.150, 6.2–6.6.104, 6.7–6.12.45, 6.13–6.16.0; fixed in 5.15.192, 6.1.151, 6.6.105, 6.12.46, 6.16.1, 6.17-rc1

PoC: CVE-2026-14962

Wordpress Plugin ELEX WooCommerce Request a Quote unauthenticated SQL injection

PoC: CVE-2026-39987_POC

Marimo WS Preauth RCE

PoC: CVE-2026-79294

CVE-2026-79294 — Stored XSS in Moonshot AI Kimi's HTML artifact Preview, delivered through the public Share view, leading to session token exfiltration and demonstrated account takeover. Responsible disclosure advisory.

PoC: cve-2026-43499-aak-an00

Honor WIN RT (AAK-AN00) CVE-2026-43499 temporary root - research notes

PoC: cve-2024-30350-research-notes

Research notes for CVE-2024-30350

PoC: CVE-2026-85612

OpenPanel Unauthenticated Server-Side Request Forgery (SSRF)

PoC: CVE-2026-15667

CVE-2026-15667 WordPress Event Solution LFI POC

PoC: hackcar-writeup

Writeup: Hackcar - DockerLabs (Node.js Inspector RCE + CVE-2025-55182 React2Shell)

PoC: CVE-2026-15253

Easy Media Replace <= 0.2.0 - Authenticated (Author+) Stored Cross-Site Scripting

PoC: CVE-2026-19794

WP-Stats <= 2.56 - Unauthenticated Stored Cross-Site Scripting

PoC: CVE-2026-65540

Popup for CF7 with Sweet Alert <= 1.6.5 - Cross-Site Request Forgery

PoC: CVE-2026-33017

Simple Proof Of Concept about CVE 2026-33017

PoC: CyberSecurity-Pentest-Lab

CVE-2004-2687 (Distcc 3.2.1) exploitation, methodology & remediation — Metasploitable2 lab

PoC: CVE-2026-85706_docker_exp

CVE-2026-85706_docker_exp

PoC: netty-resolver-dns-check

CVE-2026-45674 / CVE-2026-47691 / CVE-2026-45673: offline checker for DNS cache poisoning in io.netty:netty-resolver-dns - and whether your app actually uses that resolver. Spring WebClient on Reactor Netty uses it by default, although it is not in your pom.xml.

PoC: CVE-2026-41089-Netlogon-RCE-PoC

CVE-2026-41089 Netlogon RCE PoC — security research, vulnerability validation & defensive testing.

PoC: secdim-assurance-drift-challenge

SecDim Challenge Builder repro inspired by CVE-2026-88861: AAL1 MFA bypass at privileged credential boundary

PoC: CVE-2026-20516

Write-up and proof of concept for CVE-2026-20516: MediaTek Android TV MiracastService confused deputy vulnerability.

PoC: Metasploitable2-Reconnaissance-and-UnrealIRCd-Backdoor-Exploitation

End-to-end recon and exploitation of a known backdoor (CVE-2010-2075) on Metasploitable2 using Nmap and Metasploit.

PoC: CVE-2026-79298

CVE-2026-79298 - Incomplete remediation of UEFI Secure Boot bypass in Howyar SysReturn. The IA-32 boot path (BOOTia32.efi) was never patched after CVE-2024-7344, shipping the same revoked custom PE loader until July 2026.

PoC: CVE-2026-51990

CVE-2026-51990 - Draft or TODO

PoC: AfterLife

Revocation persistence detection lab: when the password reset succeeds but the attacker never leaves. Reproduces the Strapi CVE-2026-22706 conditional-revocation bug, its fix, a three-rule detection pack, and the naive rule that misses it.

PoC: CVE-2026-18351

CVE-2026-18351 — Drag and Drop File Upload for Elementor Forms <= 1.6.0 Unauthenticated Arbitrary File Upload -> RCE

PoC: Exploit-CVE-2026-18351

Drag and Drop File Upload for Elementor Forms - Unauthenticated Arbitrary File Upload to RCE.🔥

PoC: scadapack-secure-lock-poc

Sanitized offline fixture verifier for CVE-2026-81861 in SCADAPack Secure Lock

PoC: retbleed-speculative-execution-poc

Reproduction of the Retbleed (CVE-2022-29900/29901) micro-architectural attack in gem5. RSB underflow, Flush+Reload side-channel leak, and a verified lfence mitigation.

PoC: CVE-2026-41089-Netlogon

🛡️ Official AI Security Tool diagnostic module for CVE-2026-41089 (Windows Netlogon Stack Buffer Overflow RCE). Features technical writeup, attack architecture, IoCs, and mitigation strategy.

PoC: OMG_KILLER

Автоатакующий скрипт на базе эксплойтов CVE-2024-37890 и OOM 2026

PoC: CVE-2026-19490-check

Safely detect Citrix NetScaler SAML auth bypass CVE-2026-19490

PoC: CVE-2026-78804_Dolibarr_authenticated_SQL_injection

The action responsible for setting the per-warehouse stock alert threshold (`seuil_stock_alerte`) accepts user-controlled input and later incorporates it into an SQL query without proper numeric casting or parameter binding. #dolibarr #exploit

PoC: TryHackMe-Blue-MS17-010

Walkthrough, threat analysis, and remediation guide for CVE-2017-0144 (EternalBlue).

PoC: CVE-2026-0303

CVE-2026-0303 POC

PoC: CVE-2026-73786

Might be used to share PoC and findings regarding CVE-2026-73786 in the future

PoC: inference-gateway-PoC

PoC — cross-origin requests reuse the configured provider API key in inference-gateway (GHSA-5293-fcm6-fh8v, CVE-2026-87009, CVSS 5.4).

PoC: cve-2026-86060

Mikrotik CVE-2026-86060 Score 9.2 Critical

PoC: CVE-2016-3223

CVE-2016-3223 - Draft or TODO

PoC: RootMyVivo-Exploit

GhostLock (CVE-2026-43499) exploit fork for RootMyVivo Neo — iQOO Neo 11 (PD2520, SM8750, 6.6.89). For authorized research on own devices only.

PoC: CVE-2025-27636-RCE-in-Apache-Camel

CVE-2025-27636 PoC written in Python

PoC: CVE-2026-77578

PoC for CVE-2026-77578 - Authenticated Arbitrary Local File Read in Xibo CMS

PoC: openfire-ssrf-cve-2019-18394

PoC for CVE-2019-18394: unauthenticated full-read SSRF in Openfire <= 4.4.2 FaviconServlet

PoC: Exploit-CVE-2023-6063-PoC-Vuln

CVE-2023-6063-PoC Exploit

PoC: cve-2026-41940-PoC-Linux

CVE-2026-41940 PoC - Linux/Termux Compatible Version

PoC: CVE-2026-11387-WooCommerce-SMS-OTP

SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress; SMS Alert <3.9.6; Unauthenticated Privilege Escalation (Forced Password Reset)

PoC: HTB_Helix_CVE-2023-34468

Writeup of the Hackthebox Helix machine

PoC: CVE-2026-79387-PbootCMS-SQL-Injection

CVE-2026-79387-PbootCMS-SQL-Injection

PoC: Mikrotrick_POC

Testing tool for the Mikrotrick exploit (CVE-2026-67276)

PoC: CVE-2024-44625-Gogs-RCE-0.13.0

No issue for run this exploit.

PoC: CVE-2025-3248

An educational reference and defensive analysis of CVE-2025-3248, a critical code injection vulnerability affecting Langflow.

PoC: CVE-2026-67401-cPanel-EmailTrack-SQLi

CVE-2026-67401 cPanel & WHM EmailTrack SQL Injection — IOC scanner, compromise detection, patch verification, incident response and remediation toolkit.

PoC: CVE-2026-67401

poc in python for CVE-2026-67401

PoC: FortiLOL

FortiClient FortiShield exploit (CVE-2015-5736) for Windows 10 1809

PoC: CVE-2026-67401

CVE-2026-67401 - Draft or TODO

PoC: CVE-2026-62201-OpenClaw-SSRF

Deep-dive analysis of CVE-2026-62201: OpenClaw sandbox exec-server network policy bypass (SSRF). Root cause, vulnerable vs patched code, exploitation, detection, remediation.

PoC: CVE-2024-2961-XXE-Exploit

CVE-2024-2961 (CNEXT) PHP file-read to RCE exploit adapted to an XXE/CTF channel

PoC: Certighost_CVE-2026-54121

AD CS 证书身份伪造漏洞,属于ESC(Exploit Certification)系列 的新成员

PoC: CVE-2026-83991-writeup-and-poc

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83991

PoC: CVE-2026-19089-WooCommerce-Tyche

CVE-2026-19089 WooCommerce Tych Remote Command Execution

PoC: GhostLock-NVIDIA-Shield-9.2.4

Validated GhostLock CVE-2026-43499 port for NVIDIA Shield TV Pro mdarcy 9.2.4

PoC: CVE-2025-8110

CVE-2025-8110 - Gogs <=0.13.x symlink bypass -> arbitrary file write as the Gogs process user

PoC: CVE-2025-58434

CVE-2025-58434 - Flowise (CVE-2025-58434) unauthenticated account takeover via password-reset token disclosure

PoC: CVE-2025-55182

CVE-2025-55182 - React2Shell (CVE-2025-55182) unauthenticated RCE via React Server Components Flight deserialization

PoC: ClickHouse-Native-JDBC

Serpstat fork of housepower/ClickHouse-Native-JDBC 2.7.1. Fixes the CityHash128 checksum defect behind "Checksum doesn't match: corrupted data" on INSERT, upgrades aircompressor to 0.27 (CVE-2024-36114). Drop-in: com.serpstat:clickhouse-native-jdbc-shaded:2.7.1-serpstat.1. Apache 2.0.

PoC: CyberhawksLab-telnetCVE

Writeup/finding of CVE-2026-24061 within the Cyberhawks lab

PoC: CVE-2026-39987

Marimo Pre Authentication RCE

PoC: sift-hardened

Security-hardened fork of sift 17.1.3 for CVE-2026-85625. Not affiliated with crcn/sift.js.

PoC: CVE-2026-82222

⚡ GHOSTLYR00T - CVE-2026-82222 GiveWP RCE Exploit Framework Unauthenticated RCE on GiveWP <= 4.16.7.1. Mass scanning, auto-detection (form/gateway/amount), multi-threading, JSON/TXT output, interactive shell. CVSS 9.8 Critical. ⚠️ Authorized testing only.

PoC: CVE-2026-85046

CVE-2026-85046 | Chrome V8 Type Confusion in Inline Array.prototype.sort (Maglev/Turbofan) | CVSS 8.8 | CWE-843 | Chrome < 152.0.7977.82

PoC: CVE-2026-74239

Sanitized XenForo write-up and proof of concept for CVE-2026-74239.

PoC: CVE-2026-73321

Sanitized XenForo write-up and proof of concept for CVE-2026-73321.

PoC: CVE-2026-73320

Sanitized XenForo write-up and proof of concept for CVE-2026-73320.

PoC: CVE-2026-73319

Sanitized XenForo write-up and proof of concept for CVE-2026-73319.

PoC: CVE-2026-73318

Sanitized XenForo write-up and proof of concept for CVE-2026-73318.

PoC: CVE-2026-73317

Sanitized XenForo write-up and proof of concept for CVE-2026-73317.

PoC: CVE-2026-73316

Sanitized XenForo write-up and proof of concept for CVE-2026-73316.

PoC: CVE-2026-73315

Sanitized XenForo write-up and proof of concept for CVE-2026-73315.

PoC: CVE-2026-73314

Sanitized XenForo write-up and proof of concept for CVE-2026-73314.

PoC: CVE-2026-73313

Sanitized XenForo write-up and proof of concept for CVE-2026-73313.

PoC: CVE-2026-73312

Sanitized XenForo write-up and proof of concept for CVE-2026-73312.

PoC: CVE-2026-73311

Sanitized XenForo write-up and proof of concept for CVE-2026-73311.

PoC: CVE-2026-73310

Sanitized XenForo write-up and proof of concept for CVE-2026-73310.

PoC: CVE-2026-73309

Sanitized XenForo write-up and proof of concept for CVE-2026-73309.

PoC: guardskill

Read-only scanner for git settings that let a repository run code in coding agents (Claude Code, Codex, Cursor, Copilot). Covers the GitSpawn class and CVE-2026-45033. No dependencies, no network, no telemetry.

PoC: cve-2010-4221-lab

From patch to RCE: hand-built exploit for CVE-2010-4221 (ProFTPD TELNET IAC stack overflow), with the full failure-driven journey documented

PoC: netty-http-check

CVE-2026-59903 / CVE-2026-33870: offline checker for the 14 io.netty:netty-codec-http CVEs. Netty ships all modules under one version number but each has its own fix version — 4.1.136.Final (the netty-codec-http2 answer) still leaves this module exposed; it needs 4.1.137.Final / 4.2.17.Final.

PoC: metasploit-lab-report

Educational penetration testing lab report demonstrating exploitation of vsftpd 2.3.4 backdoor vulnerability (CVE-2011-2523) in Metasploitable 2 using Metasploit Framework. Includes detailed documentation of reconnaissance, vulnerability analysis, configuration, verification, and exploitation phases.

PoC: CVE-2026-8069

Technical write-up and PoC for CVE-2026-8069 in Acer NitroSense and PredatorSense

PoC: stylesmuggler-adobe-patches-mageos

composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Mage-OS stores, via cweagans/composer-patches. Companion to stylesmuggler-adobe-patches (Magento).

PoC: CVE-2026-8732-PoC

CVE-2026-8732 | WP Maps Pro <= 6.1.0 Unauth Admin Creation

PoC: stylesmuggler-adobe-patches

composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Magento, via cweagans/composer-patches. Auto-selects the patch for your Magento version.

PoC: cve-2026-40369-exploit

Exploit inspired by `https://voidsec.com/cve-2026-40369-browser-sandbox-escape/`. Use Feature_RestrictKernelAddressLeak and forge token to Elevate privileges

PoC: CVE-2026-83548-CVE-2026-83549

CVE-2026-83548, CVE-2026-83549, - Draft or TODO - https://github.com/rapid7/metasploit-framework/pull/21883

PoC: hdwebmobile-booking-appointments

Sell bookable services and appointments through WooCommerce -- closes CVE-2026-2931 by construction.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free