Feed/GHSA-hjwh-xvfw-qrwj
GHSA-hjwh-xvfw-qrwjMEDIUMCVSS 5.5

SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses

Published Aug 19, 2026·Updated Aug 19, 2026

NVD Description

### Summary mcp-searxng version 1.11.0 exposes SearXNG Basic Authentication credentials embedded in the `SEARXNG_URL` environment variable. When the server starts in STDIO mode and an MCP client connects, the complete `SEARXNG_URL`, including its username and password, is sent to the client through an MCP `notifications/message` logging notification. Additionally, when URL validation fails, the complete credential-bearing URL is included in the configuration error. This error is logged through MCP and returned to the client as a JSON-RPC error response. For example, a value such as: ```text http://username:password@searxng.example.com ``` is exposed without redaction. A connected MCP client or anyone with access to captured server logs may recover the SearXNG credentials and use them to access the configured SearXNG instance. The issue was confirmed in: ```text mcp-searxng 1.11.0 ``` Suggested severity: **Medium** ### Details mcp-searxng supports SearXNG Basic Authentication by embedding credentials in the URL userinfo component: ```text https://username:password@searxng.example.com ``` The project contains a redaction function named `redactSearxngInstanceUrl()`, but it is not used in several logging and error-handling paths. #### Startup console disclosure In `src/index.ts:373-378`, the server retrieves the raw SearXNG URLs and writes them directly to stderr: ```typescript const searxngInstances = getSearxngInstances(); if (searxngInstances.length > 0) { console.error(`🌐 SearXNG URLs: ${searxngInstances.join("; ")}`); } ``` `getSearxngInstances()` returns the unmodified environment-variable values. Relevant code in `src/searxng-instances.ts:25-38`: ```typescript export function parseSearxngUrls( raw: string | undefined = process.env.SEARXNG_URL ): string[] { if (raw === undefined) { return []; } return raw .split(";") .map((entry) => entry.trim()) .filter((entry) => entry !== ""); } export function getSearxngInstances(): string[] { return parseSearxngUrls(); } ``` #### MCP logging notification disclosure After the MCP client connects, `src/index.ts:388-393` sends the complete URL through the MCP logging interface: ```typescript const searxngInstances = getSearxngInstances(); logMessage( mcpServer, "info", `SearXNG URLs: ${ searxngInstances.length > 0 ? searxngInstances.join("; ") : "not configured" }` ); ``` `logMessage()` passes this value to `sendLoggingMessage()` in `src/logging.ts:15-25`: ```typescript mcpServer.sendLoggingMessage({ level, data: notificationData }); ``` As a result, the connected MCP client receives a message containing the username and password: ```json { "method": "notifications/message", "params": { "level": "info", "data": { "message": "SearXNG URLs: http://username:password@searxng.example.com" } }, "jsonrpc": "2.0" } ``` #### Configuration error disclosure The URL validation function includes the complete unredacted value in error messages. Relevant code in `src/searxng-instances.ts:44-52`: ```typescript export function validateSearxngInstanceUrl( value: string ): string | null { try { const url = new URL(value); if (!["http:", "https:"].includes(url.protocol)) { return `SEARXNG_URL invalid protocol for "${value}": ${url.protocol}`; } } catch { return `SEARXNG_URL invalid format: ${value}`; } return null; } ``` The validation error is aggregated by `validateEnvironment()` in `src/error-handler.ts:175-203`: ```typescript const validationError = validateSearxngInstanceUrl(searxngUrl); if (validationError) { issues.push(validationError); } ``` The complete error is then thrown from `src/search.ts:689-693`: ```typescript const validationError = validateEnvironment(); if (validationError) { logMessage(mcpServer, "error", "Configuration invalid"); throw new MCPSearXNGError(validationError); } ``` The tool handler in `src/index.ts:254-260` sends the error message and stack trace through MCP logging, then rethrows it: ```typescript logMessage( mcpServer, "error", `Tool execution error: ${ error instanceof Error ? error.message : String(error) }`, { tool: name, args: args, error: error instanceof Error ? error.stack : String(error) } ); throw error; ``` Rethrowing the error causes the same unredacted credential-bearing URL to be returned in the JSON-RPC error response. #### Existing redaction function is not used The project already contains a suitable redaction function in `src/searxng-instances.ts:57-69`: ```typescript export function redactSearxngInstanceUrl( raw: string ): string { try { const url = new URL(raw); if (!url.username && !url.password) { return raw; } url.username = ""; url.password = ""; return url.toString(); } catch { return raw.replace( /^([a-zA-Z][a-zA-Z0-9+.-]*:\/\/)[^/]*@/, "$1" ); } } ``` However, this function is not applied before startup logging, MCP logging, or configuration error construction. The MCP manifest also marks `SEARXNG_URL` as non-secret in `.mcp/server.json:20-25`: ```json { "name": "SEARXNG_URL", "description": "URL of your SearXNG instance", "isRequired": true, "isSecret": false, "format": "string" } ``` Because credentials may be embedded in this variable, it should be classified as a secret. ### PoC The following proof of concept uses fake credentials. A real SearXNG server is not required. #### Requirements ```text Node.js 20 or newer npm mcp-searxng 1.11.0 source code ``` #### Build the application ```bash unzip mcp-searxng-main.zip cd mcp-searxng-main npm ci npm run build ``` #### Test 1: Credential disclosure through MCP logging Create an MCP initialization request: ```bash cat > /tmp/mcp-init.jsonl <<'EOF' {"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"credential-leak-poc","version":"1.0.0"}}} EOF ``` Start the server with fake credentials embedded in a valid HTTP URL: ```bash SEARXNG_URL='http://MCP_POC_USER_7391:MCP_POC_PASS_7391@127.0.0.1:9' \ timeout 8s node dist/cli.js \ < /tmp/mcp-init.jsonl \ 2>&1 | tee credential-log-leak.txt ``` Search the output for the credentials: ```bash grep -nE \ 'MCP_POC_USER_7391|MCP_POC_PASS_7391' \ credential-log-leak.txt ``` #### Observed result The complete credential-bearing URL is exposed: ```text SearXNG URLs: http://MCP_POC_USER_7391:MCP_POC_PASS_7391@127.0.0.1:9 ``` It is also delivered to the MCP client: ```json { "method": "notifications/message", "params": { "level": "info", "data": { "message": "SearXNG URLs: http://MCP_POC_USER_7391:MCP_POC_PASS_7391@127.0.0.1:9" } }, "jsonrpc": "2.0" } ``` This confirms that a connected MCP client can recover the configured username and password without accessing the host environment. #### Test 2: Credential disclosure through JSON-RPC errors Create initialization and tool-call requests: ```bash cat > /tmp/mcp-error-poc.jsonl <<'EOF' {"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"credential-error-poc","version":"1.0.0"}}} {"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"searxng_web_search","arguments":{"query":"credential leak test"}}} EOF ``` Start the server with a credential-bearing URL that uses an unsupported protocol: ```bash SEARXNG_URL='ftp://MCP_POC_USER_7391:MCP_POC_PASS_7391@example.invalid' \ timeout 8s node dist/cli.js \ < /tmp/mcp-error-poc.jsonl \ 2>&1 | tee credential-error-leak.txt ``` Search the response: ```bash grep -nE \ 'MCP_POC_USER_7391|MCP_POC_PASS_7391' \ credential-error-leak.txt ``` #### Observed result The complete URL is exposed in the MCP logging notification: ```text Tool execution error: Configuration Issues: SEARXNG_URL invalid protocol for "ftp://MCP_POC_USER_7391:MCP_POC_PASS_7391@example.invalid": ftp: ``` It is also returned directly in the JSON-RPC error: ```json { "jsonrpc": "2.0", "id": 2, "error": { "code": -32603, "message": "Configuration Issues: SEARXNG_URL invalid protocol for \"ftp://MCP_POC_USER_7391:MCP_POC_PASS_7391@example.invalid\": ftp:" } } ``` The raw username and password are therefore exposed through both logging and protocol responses. ### Impact This is a sensitive credential disclosure vulnerability. The following parties may obtain the credentials: 1. A connected MCP client receiving logging notifications. 2. A client capable of invoking a tool and receiving JSON-RPC errors. 3. A user or process with access to captured stderr output. 4. A centralized logging or monitoring system collecting application logs. 5. Other users with access to shared log files or container logs. The exposed credentials may allow an attacker to authenticate directly to the configured SearXNG instance. Depending on the SearXNG deployment and the permissions associated with the account, this may allow: 1. Unauthorized use of a private SearXNG service. 2. Access to functionality restricted through Basic Authentication. 3. Consumption of private server resources. 4. Exposure of information available only to authenticated users. 5. Further account compromise where the credentials have been reused. The default STDIO transport limits the exposure to the connected parent MCP client and local logging environment. However, MCP clients should not receive upstream service credentials, and the project security documentation explicitly treats credentials embedded in `SEARXNG_URL` as secrets that must be redacted. ### Suggested mitigation Apply `redactSearxngInstanceUrl()` before including any SearXNG URL in console or MCP logging: ```typescript const redactedInstances = getSearxngInstances() .map(redactSearxngInstanceUrl); logMessage( mcpServer, "info", `SearXNG URLs: ${ redactedInstances.length > 0 ? redactedInstances.join("; ") : "not configured" }` ); ``` Do not include raw configuration values in validation errors. A generic error can be returned instead: ```typescript return `SEARXNG_URL entry has an unsupported protocol: ${url.protocol}`; ``` For malformed URLs: ```typescript return "SEARXNG_URL contains an invalid URL"; ``` The following additional changes are recommended: 1. Redact URLs before writing them to stderr. 2. Redact secrets before sending MCP logging notifications. 3. Avoid including raw environment-variable values in exceptions. 4. Avoid returning detailed stack traces containing secrets to MCP clients. 5. Mark `SEARXNG_URL` as secret in `.mcp/server.json`: ```json "isSecret": true ``` 6. Add regression tests that assert usernames and passwords never appear in: * stderr output * MCP logging notifications * JSON-RPC error responses * stack traces * configuration resources

Affected Packages (1)

mcp-searxngNPM
Fixed in 1.12.0

Public Exploits & PoCs100 found

PoC: YellowKey-BitLocker-CVE-2026-45585

YellowKey BitLocker recovery - bitlocker yellowkey, yellowkey bitlocker, CVE-2026-45585, yellowkey github, yellowkey vulnerability, yellowkey CVE, TPM, BitLocker recovery key backup, Windows 10/11, CLI GUI, portable audit tool. Download:🡇

13

PoC: pixel-ksu-root

adb-driven KernelSU loader for stock Google Pixel: temporary kernel R/W via CVE-2026-43499 (GhostLock), then late-loads a signature-matched kernelsu.ko for the running KMI. Manager-agnostic.

5

PoC: CVE-2026-21962-Blog

CVE-2026-21962 Açığı için blog sayfası oluşturdum.

1

PoC: PoC-and-yara-rules-of-CVE-2025-59528-Flowise-has-Remote-Code-Execution-vulnerability

poc and yara rules

1

PoC: CVE-2026-72898

Metabase SQLi

1

PoC: CVE-2026-19478

GitLab Code injection

1

PoC: CVE-2026-75604

CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing

1

PoC: CVE-2026-19632

CVE-2026-19632 - TranslatePress One-Day PoC

1

PoC: CVE-2026-56705

CVE-2026-56705 - Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection (ODBC TraceFile arbitrary file write). PoC, Docker lab and negative test included.

1

PoC: CVE-2026-75604-poc

CVE-2026-75604 Next.js Windows RCE poc

1

PoC: CVE-2026-4692-trust-me-im-in-rdm

Firefox BrowsingContext field-sync authz bypass (N-day, bug 2017643): forged PContent::CommitBrowsingContextTransaction sets InRDMPane=true from a compromised content process - parent applies it. Prerequisite primitive for privileged-UI touch-event injection.

1

PoC: CVE-2022-28906-POC

CVE-2022-28906 Proof of concept in Python3

1

PoC: CVE-2026-41551

ROS# 路径遍历漏洞(CVE-2026-41551)

1

PoC: cve-2022-42475-poc

Proof of Concept (PoC) for research and controlled laboratory validation of CVE-2022-42475, a critical heap-based buffer overflow vulnerability affecting the SSL-VPN service in certain versions of FortiOS.

1

PoC: PaperCut-CVE-2026-81578-82078

Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078

PoC: vankyo-s30-bootloader-unlock

Vankyo MatrixPad S30 (Unisoc SC9863A) — Bootloader unlock via CVE-2022-38694 FDL1 method

PoC: CVE-2026-21962-Blog

CVE-2026-21962 Açığı için blog sayfası oluşturdum.

PoC: hdwebmobile-formula-pricing

WooCommerce plugin: safe formula-based product pricing, closing CVE-2026-4001's eval()-based RCE

PoC: CVE-2026-82286-gpt-crawler-Arbitrary-File-Write

CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS 8.6, CWE-22.

PoC: CVE-2026-24061-payload

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

PoC: CVE-2026-66384

CVE-2026-66384 - Draft or TODO

PoC: CVE-2026-33017-PoC-Reverse-Shell

CVE-2026-33017 PoC Reverse Shell

PoC: CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules

CVE-2026-33057 - Mesop Unauthenticated RCE PoC and yara rules

PoC: CVE-2026-10036-speechbrain-rce

SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.

PoC: CVE-2025-55182-poc

I know you are probably here from Hack the Box, if so, yes this one actually works.

PoC: Project-CVE-2026-50751

IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.

PoC: CTT-Enhanced-CVE-2026-46339-Exploit-Engine

A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.

PoC: Zimbra-CVE-2026-73570-Rules

Wazuh Rules for Detection Zimbra (CVE-2026-73570).

PoC: CVE-2022-46169

Cacti 1.2.22 unauthenticated command injection

PoC: CVE-2024-23897

Jenkins CVE-2024-23897 — CSRF-crumb aware PoC

PoC: CVE-2025-10952-ml-logger-AFR

PoC for CVE-2025-10952 — ml-logger unauthenticated arbitrary file read. CVSS 5.3

PoC: CVE-2026-65643

CVE-2026-65643 - Draft or TODO

PoC: cve-2023-23397-detection-lab

Detection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry.

PoC: fastjson-cve

fastjson-cve-2026-16723

PoC: CVE-2026-23751-poc

Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP Remoting)

PoC: CVE-2023-27350-CVE-2023-27351

CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO

PoC: Project-CVE-2026-33017

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

PoC: CVE-2026-70463

Testing CVE-2026-70463 by Fyyre

PoC: 2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report

Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server infrastructure, impact across 140,000+ cloud tenants, root-cause findings, and phased mitigation strategies.

PoC: CVE-2026-20131-Post-Incident-Written-Report

Post-incident report on CVE-2026-20131 (CVSS 10.0), a Cisco FMC insecure deserialization vulnerability exploited by Interlock ransomware. Details root-cause analysis, lateral movement tactics, and emergency containment strategies.

PoC: ghostlock-pfem10

GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes

PoC: htb-labs-connected

Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via FreePBX and incron.

PoC: spring-ai-sibling-loop-poc

Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)

PoC: mssharepoint-scanner

A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

PoC: weblogic

Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)

PoC: CVE-2021-27876-veritas-backup

Metasploit module: Veritas Backup Exec Agent SHA-auth NDMP remote code execution (CVE-2021-27876/27877/27878)

PoC: rmg-s9180-fzg1

Root My Galaxy SM-S9180 (dm3q) S9180ZHS8FZG1 payload port - CVE-2026-43499 + KernelSU LKM

PoC: hacktivity-vulns-exploits-lab

Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).

PoC: CVE-2026-55040-Mass-Exploit

CVE-2026-55040

PoC: Project-CVE-2026-75604

A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilities. Deploys reverse shells and webshells via path traversal, with built-in target verification and proxy support for seamless integration into standard pentest workflows.

PoC: CVE-2026-18963

CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector

PoC: CVE-2015-3246

CVE-2015-3246

PoC: CVE-2015-5287

CVE-2015-5287

PoC: htb-labs-nexus

Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access, and privilege escalation through a vulnerable Gitea template synchronization service.

PoC: Cisco-CVE-2026-20303-More

CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313

PoC: CVE-Ubiquiti

CVE-2026-77542, CVE-2026-77543, CVE-2026-77545, CVE-2026-77550, CVE-2026-77551, CVE-2026-77552, CVE-2026-77553, CVE-2026-77554, CVE-2026-77557 - Draft or TODO

PoC: CVE-2026-18431

CVE-2026-18431 - Draft or TODO

PoC: CVE-2026-8467

CVE-2026-8467 - Draft or TODO

PoC: CVE-2026-50787

Security advisory for CVE-2026-50787: uncontrolled resource consumption in e-SIC Livre CAPTCHA generation leading to remote denial of service.

PoC: solarview-ics-vulnerability-analysis

Threat model and vulnerability analysis of Contec SolarView Compact (CVE-2022-29303)

PoC: CVE-2026-72898-metabase-sqli

Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)

PoC: By-Poloss..-..CVE-2026-18080

Poc CVE-2026-18080

PoC: CVE-2026-63520

POC pre-auth RCE on Sharepoint chain

PoC: f_hid-4.14-backports

Backports of three published f_hid fixes (incl. CVE-2026-31721, CVE-2026-31606) to an EOL Linux 4.14.190 Android vendor kernel, with on-device verification records.

PoC: chrome-vuln-scanner

Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome extension leveraging social engineering.

PoC: CVE-2026-19912-CVE-2026-19913-CVE-2026-19914

CVE-2026-19912, CVE-2026-19913, CVE-2026-19914

PoC: CVE-2026-19632-POC

PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure

PoC: ghostlock-infinix-hot70

Proof-of-concept kernel exploit for GhostLock (CVE-2026-43499) on the Infinix Hot 70.

PoC: CVE-2025-2945-pgAdmin-RCE

PoC for CVE-2025-2945 — pgAdmin 4 authenticated eval() injection RCE, CVSS 9.9

PoC: CVE-2026-63072

CVE-2026-63072

PoC: CVE-2026-76904

PostGIS SQL Injection GeoTools

PoC: CVE-2014-085

ZooKeeper 未授权访问漏洞(CVE-2014-085)PoC 及靶场

PoC: hdwebmobile-photo-video-reviews

WooCommerce plugin: photo & video product reviews, closing CVE-2026-12684's unauthenticated-upload vulnerability class by construction

PoC: Exploit-CVE-2026-56705

CVE-2026-56705 — Adminer < 5.4.3 Unauthenticated RCE via MSSQL PDO DSN Injection

PoC: CVE-2026-73570

Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)

PoC: vivo-root-build

vivo/iQOO 提权 so 编译(CVE-2026-43499)

PoC: CVE-2026-72530-TrueConf-Sandbox-Escape-

Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y Sandbox Escape** en TrueConf Server.

PoC: CVE-2021-41773-Exploit

CVE-2021-41773 Apache HTTP Server 2.4.49 Path Traversal to RCE Exploit

PoC: cve-2026-60004

CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.

PoC: CVE-2026-68820_Mass_Exploit

CVE-2026-68820 — Mass Exploit Framework Edition.

PoC: CVE-2026-58073-check

Safely detect Veeam Service Provider Console auth bypass CVE-2026-58073

PoC: CVE-2026-18963

Nuclei template to discover Keycloak reset-credentials endpoints related to CVE-2026-18963 exposure validation.

PoC: CVE-2020-1472

CVE-2020-1472

PoC: CVE-2026-32635-Angular-XSS-Mitigation-

Demostracion educativa de mitigacion y deteccion de CVE-2026-32635: XSS en atributos i18n de Angular.

PoC: CVE-2018-16763_fuel_cms_exploit

A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.

PoC: CVE-2026-26211

Public disclosure for CVE-2026-26211, a stored XSS vulnerability affecting Ekushey Project Manager CRM v5.0.

PoC: keycloak-CVE-2026-18963

PoC, Dockerfile playground and root cause from patch diff analysis.

PoC: CVE-2026-17532-lab

CVE-2026-17532 Docker Lab.

PoC: Wildfire

CVE-2026-39154, Stored XSS in CometChat JS SDK

PoC: Trespasser

CVE-2026-74970, Fission site isolation bypass in Firefox WebRender

PoC: Palimpsest

CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)

PoC: SkeletonKey

CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox

PoC: Revenant

CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)

PoC: CVE-2026-73570

PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)

PoC: EDRKiller

Use cve-2026-36425 killer edr,360 can killer

PoC: RootMyVivo

One-click root for vivo/iQOO devices on locked bootloader | CVE-2026-43499 + KernelSU

PoC: Exploit-For-CVE-2026-18963

Exploit for CVE-2026-18963 by BlackHatExploitation

PoC: gha-lab-aaaaa1cc3e

GitHub Actions workflow sandbox for CVE-2025-67727 reproduction

PoC: gha-lab-f1c8785cc8

GitHub Actions workflow sandbox for CVE-2025-46820 reproduction

PoC: CVE-2026-16348

TP-Link Archer BE800 V1 — VPN Key Injection RCE

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free