Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Reproduced Vulnerabilities

Every card below is a CVE our Claude Code agent reproduced end-to-end: it reads the PoC, rebuilds the real vulnerable system in an isolated Docker sandbox, launches a real exploit, and records the whole run with asciinema. A "VULNERABLE:" line is hard proof the exploit fired.

200 vulnerabilities reproduced with live recordings
Full sandbox recordings + exploit POC are a Pro+ exclusive. Upgrade to Pro+ — limited ¥499/mo

5

CVE-2026-77751 High CVSS 8.8
Path Traversal in MISP Object Template Resolution During STIX Import and Export in misp-stix library
Pro+ — watch recording Unlock full PoC steps
CVE-2026-72848 High CVSS 8.6
langchain-community SitemapLoader Does Not Apply restrict_to_same_domain to Nested Sitemap Index Entries, Allowing Server-Side Request Forgery
Pro+ — watch recording Unlock full PoC steps
CVE-2026-72860 High CVSS 8.5
9router Server-Side Request Forgery via /api/provider-nodes/validate Because the IPv4-Mapped IPv6 Denylist Check Is Unreachable
Pro+ — watch recording Unlock full PoC steps
CVE-2026-66393 High CVSS 7.5
NLTK before 3.9.4 Denial of Service via JSONTaggedDecoder
Success marker: VULNERABLE: unhandled RecursionError: maximum recursion depth exceeded in JSONTaggedDecoder.decode_obj — process crashed (DoS)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-72818 High CVSS 7.5
NLTK TweetTokenizer URL Pattern Backtracks Catastrophically on Naked-Domain-Like Input
Success marker: VULNERABLE: ReDoS confirmed - 5001-char input stalled tokenizer for 4288 ms (catastrophic backtracking in URLS naked-domain branch)
Pro+ — watch recording Unlock full PoC steps

8

CVE-2026-62677 High CVSS 8.8
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
Success marker: VULNERABLE: sys_os_read via attacker-controlled os_env.cwd=/root/omnigent_secrets exfiltrated PROOF_ed11a79ef2141c52
Pro+ — watch recording Unlock full PoC steps
CVE-2026-71963 High CVSS 8.8
Hermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config Injection
Success marker: VULNERABLE: RCE via git core.fsmonitor config injection - proof token PROOF_f02f5301d82cea58 exfiltrated by attacker-controlled fsmonitor command
Pro+ — watch recording Unlock full PoC steps
CVE-2026-41449 High CVSS 7.8
UAC < 3.3.0 Command Injection via run_command.sh
Success marker: VULNERABLE: command injection confirmed - injected command wrote PROOF_69638f3baa6137cf to /tmp/proof.txt (eval in _run_command, run_command.sh)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-41450 High CVSS 7.8
UAC < 3.3.0 Command Injection via command_collector.sh
Success marker: VULNERABLE: arbitrary command executed via %line% injection; proof token PROOF_a610d96b1f12d0f0 was exfiltrated through the eval of the %line%-substituted command into /output
Pro+ — watch recording Unlock full PoC steps
CVE-2026-41451 High CVSS 7.8
UAC < 3.3.0 Command Injection via User Substitution in parse_artifact.sh
Success marker: VULNERABLE: RCE confirmed — crafted /etc/passwd user "pwn$(cp /flag.txt /uac_pwned)"; /uac_pwned contains token: PROOF_6e7a09c41922e583
Pro+ — watch recording Unlock full PoC steps
CVE-2026-55241 High CVSS 7.5
Checkmate: Pre-auth Denial of Service via File Upload on Registration
Success marker: VULNERABLE: node RSS grew from 156MB to 1108MB (+952MB, ~7x amplification) after 20 concurrent 100MB profileImage uploads — memory-exhaustion DoS
Pro+ — watch recording Unlock full PoC steps
CVE-2026-71862 High CVSS 7.5
Checkmate: Sensitive Bearer Token Exposure via Public Status Pages When showURL Setting is Enabled
Success marker: VULNERABLE: unauthenticated /api/v1/status-page/cve-page leaked monitor secret PROOF_563c1caed42db72a
Pro+ — watch recording Unlock full PoC steps
CVE-2026-49114 High CVSS 7.1
ONNX symlink-following and path-traversal arbitrary file write
Success marker: VULNERABLE: tensor x bytes (4000B) appended into /flag.txt through pre-planted symlink /tmp/x -> /flag.txt; proof token PROOF_0b9172ba7b6795de exfiltrated
Pro+ — watch recording Unlock full PoC steps

5

CVE-2026-62316 High CVSS 8.8
Microsoft UFO: DNS Rebinding → Unauthenticated File Read / Command Execution
Success marker: VULNERABLE: /mcp answered with Host: attacker.com (no Host/Sec-Fetch-Site validation); execute_command 'cat /flag.txt' returned PROOF_47a6b3d47fae4f92
Pro+ — watch recording Unlock full PoC steps
CVE-2026-77354 High CVSS 8.7
kin-openapi: Uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
Success marker: VULNERABLE: uncontrolled heap allocation (~1.6GB) exceeds 1GB mem_limit -> reproducer OOM-killed (exit 137)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-61824 High CVSS 8.2
Defuddle: XSS via unescaped attribute interpolation in site extractors
Success marker: VULNERABLE: proof token PROOF_325147b177739780 found in extracted image HTML - unescaped og:image interpolation confirmed
Pro+ — watch recording Unlock full PoC steps
CVE-2026-68508 High CVSS 7.8
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
Success marker: VULNERABLE: hydra-core 1.3.3 — untrusted config target "os.system" executed; retrieved proof token PROOF_c660833ca1783d4e from /proof.txt via docker exec (RCE confirmed)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-54134 High CVSS 7.0
OctoPrint: File exfiltration possible via query parameters on upload endpoints
Success marker: VULNERABLE: reserved-field query-param injection; token PROOF_839a15ff482fb83f exfiltrated via /api/files/local?path=/flag.txt
Pro+ — watch recording Unlock full PoC steps

8

CVE-2026-78209 High CVSS 8.2
exceljs through 4.4.0 CSV Formula Injection via Unescaped Cell Values
Success marker: VULNERABLE: unescaped formula in exported CSV: user_input,"=cmd|'/bin/sh -c ""echo PROOF_f6fba9086be3b9a3 > /tmp/pwned"""
Pro+ — watch recording Unlock full PoC steps
CVE-2026-49360 High CVSS 7.8
Recce server has unauthenticated SQL execution that allows local file read/write through DuckDB
Success marker: VULNERABLE: unauthenticated query read /flag.txt -> PROOF_1e14a3b047408c95
Pro+ — watch recording Unlock full PoC steps
CVE-2026-57998 High CVSS 7.8
better-npm-audit OS Command Injection via registry flag
Success marker: VULNERABLE: OS command injection wrote token to /proof.txt: PROOF_f3e7f5fb068ab487 --json
Pro+ — watch recording Unlock full PoC steps
CVE-2026-78206 High CVSS 7.5
exceljs through 4.4.0 Uncontrolled Resource Consumption via Unbounded xlsx Decompression
Success marker: VULNERABLE: unbounded xlsx decompression DoS — RSS grew by 612 MB (bomb expanded 300 MB) proof token: PROOF_a65d8604f3ac155b
Pro+ — watch recording Unlock full PoC steps
CVE-2026-78208 High CVSS 7.5
exceljs through 4.4.0 Path Traversal via Unvalidated addImage filename
Success marker: VULNERABLE: /root/flag.txt (PROOF_fe22008b0f9cdaa1) read via unvalidated addImage filename and embedded as xlsx media part xl/media/image1.undefined
Pro+ — watch recording Unlock full PoC steps
CVE-2026-78171 High CVSS 7.3
itsourcecode Sales and Inventory System processlogin.php sql injection
Success marker: VULNERABLE: SQLi in processlogin.php — exfiltrated token PROOF_291da78b188f5bb0 from flags table via User parameter
Pro+ — watch recording Unlock full PoC steps
CVE-2026-78180 High CVSS 7.3
alibaba-fusion next deepMerge index.tsx ConfigProvider.getContextProps prototype pollution
Success marker: VULNERABLE: Object.prototype polluted — ({}).polluted === PROOF_0c3a97c99ed9dc3b VULNERABLE: Object.prototype polluted — ({}).polluted === PROOF_0c3a97c99ed9dc3b
Pro+ — watch recording Unlock full PoC steps

8

CVE-2026-78369 High CVSS 8.8
Missing Authentication Allows Unauthorized Creation of Crypto Groups in RansomLook
Pro+ — watch recording Unlock full PoC steps
CVE-2026-75931 High CVSS 7.5
fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
Pro+ — watch recording Unlock full PoC steps
CVE-2026-76172 High CVSS 7.5
fast-uri vulnerable to host confusion via percent-encoded scheme normalization
Success marker: VULNERABLE: proof_38e5d2e652b08d41 - attacker host exfiltrated through the resolved reference (PROOF_38e5d2e652b08d41)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-78181 High CVSS 7.3
ractivejs ractive Keypath Ractive#set prototype pollution
Success marker: VULNERABLE: prototype pollution confirmed — Object.prototype.polluted = PROOF_5f92b4176538ce71 (retrieved through Ractive#set kepath handler)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-78201 High CVSS 7.3
itsourcecode Payroll System admin_class.php login sql injection
Success marker: VULNERABLE: auth bypass confirmed (status:1) and proof token PROOF_9237f39442f4751b exfiltrated via UNION SQLi
Pro+ — watch recording Unlock full PoC steps
CVE-2026-78244 High CVSS 7.3
itsourcecode Real Estate Management System search.php sql injection
Success marker: VULNERABLE: UNION SQLi exfiltrated DB flag PROOF_9ee1e8a05fde1126 via /search.php
Pro+ — watch recording Unlock full PoC steps
CVE-2026-78246 High CVSS 7.3
itsourcecode Online Clinic Management System Admin Login login.php sql injection
Success marker: VULNERABLE: SQLi auth bypass via username=admin<apostrophe>hash exfiltrated proof token PROOF_60c5c4e1bdeee685
Pro+ — watch recording Unlock full PoC steps
CVE-2026-78247 High CVSS 7.3
SourceCodester Simple Online Food Ordering System ajax.php confirm_order sql injection
Success marker: VULNERABLE: SQLi in confirm_order exfiltrated token "PROOF_b0554e88dc1d0b07" via UNION SELECT
Pro+ — watch recording Unlock full PoC steps

3

CVE-2026-76098 High CVSS 7.5
Mistune has Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
Success marker: VULNERABLE: RecursionError raised while HTML-rendering 1000-char nested-strong payload; exfiltrated token: PROOF_cf43d49ceb5be824
Pro+ — watch recording Unlock full PoC steps
CVE-2026-76072 High CVSS 7.4
Continue CLI through 1.5.47 Incomplete Destructive Command Denylist in Headless and Auto Mode
Success marker: VULNERABLE: rm -rf /home evaluates to a non-disabled policy - proof=PROOF_c26a3be4aac0c932
Pro+ — watch recording Unlock full PoC steps
CVE-2026-6561 Medium CVSS 4.7
EyouCMS Index.php edit_adminlogo unrestricted upload
Success marker: VULNERABLE: PROOF_395a8a12d7b64eac exfiltrated via edit_adminlogo arbitrary file copy into /public/static/admin/images/logo*.png
Pro+ — watch recording Unlock full PoC steps

8

CVE-2024-36401 Critical CVSS 9.8
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
Success marker: VULNERABLE: RCE confirmed - proof token PROOF_b39b4f8a10faa695 exfiltrated through the JXPath expression response of /vulnerable-example
Pro+ — watch recording Unlock full PoC steps
CVE-2026-78675 High CVSS 8.4
GitPython before 3.1.59 Local File Content Disclosure via .gitmodules
Success marker: VULNERABLE: PROOF_2f479199411791bb leaked from /flag.txt via .gitmodules [include] (MissingSectionHeaderError)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-72695 High CVSS 8.1
Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFile
Success marker: VULNERABLE: token PROOF_75a2eb44bab8cc11 was exfiltrated-then-deleted from /var/www/proof.txt via ../ traversal in MediaUploadTrait::deleteFile
Pro+ — watch recording Unlock full PoC steps
CVE-2020-26160 High CVSS 7.5
jwt-go 安全漏洞
n/a / n/a
Success marker: VULNERABLE: JWT with "aud": [] passed the audience check; secret PROOF_129359ed61425a34 exfiltrated
Pro+ — watch recording Unlock full PoC steps
CVE-2026-76846 High CVSS 7.5
Grav before 2.0.16 Information Disclosure via Twig Sandbox
Success marker: VULNERABLE: secret exfiltrated via Twig -- rendered page leaked config system.cache.redis.password = PROOF_add2bca7f7e24517
Pro+ — watch recording Unlock full PoC steps
CVE-2026-78677 High CVSS 7.5
GitPython before 3.1.59 Path Traversal via separate-git-dir
Pro+ — watch recording Unlock full PoC steps
CVE-2026-82275 High CVSS 7.5
Qwen-Agent Arbitrary File Read via Caller-Supplied Document Path
Pro+ — watch recording Unlock full PoC steps
Nagios XI 操作系统命令注入漏洞
n/a / n/a
Success marker: VULNERABLE: uid=0(root) gid=0(root) groups=0(root) + exfiltrated root-only /flag.txt containing PROOF_c7960c224e29dd26
Pro+ — watch recording Unlock full PoC steps

16

CVE-2026-67614 Critical CVSS 9.8
CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal
Success marker: VULNERABLE: unauthenticated forged-JWT gave a root shell; exfiltrated proof token PROOF_8d031b6a29a5c4b0 from /flag.txt via WebTerminal
Pro+ — watch recording Unlock full PoC steps
CVE-2026-64649 High CVSS 8.3
Next.js: Server-Side Request Forgery in Server Actions on Custom Servers
Success marker: VULNERABLE: SSRF confirmed — custom server fetched attacker-controlled host proof:9999 and exfiltrated token PROOF_25f53a62228edd33
Pro+ — watch recording Unlock full PoC steps
CVE-2026-58372 High CVSS 8.1
SeaweedFS < 4.34 - Cross-Bucket Object Deletion via DeleteObjects Request-Body Keys
Pro+ — watch recording Unlock full PoC steps
CVE-2026-78680 High CVSS 7.8
NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binary
Success marker: VULNERABLE: attacker-controlled dot binary executed, exfiltrated token PROOF_cb876d36d1a5c8f5 via dot2img
Pro+ — watch recording Unlock full PoC steps
CVE-2020-7746 High CVSS 7.5
Prototype Pollution
Success marker: VULNERABLE: observed Object.prototype.polluted = PROOF_d6e0445b96e40358 — chart.js 2.9.3 deep-merges unsanitized __proto__ into Object.prototype
Pro+ — watch recording Unlock full PoC steps
CVE-2026-78681 High CVSS 7.5
NLTK before 3.10.3 Entity Expansion DoS via ElementTree
Pro+ — watch recording Unlock full PoC steps
CVE-2026-78682 High CVSS 7.5
NLTK before 3.10.3 SSRF Protection Bypass via Proxy
Success marker: VULNERABLE: internal loopback resource exfiltrated -- fetched PROOF_0f4375b9e3b5ba5d through attacker proxy (destination 127.0.0.1 never re-validated)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-4562 High CVSS 7.3
MacCMS Timming API Endpoint Timming.php weak authentication
Pro+ — watch recording Unlock full PoC steps
CVE-2026-75838 Medium CVSS 5.1
DOMPurify before 3.4.13 Cross-Site Scripting via IN_PLACE hook
Success marker: VULNERABLE: after IN_PLACE sanitize the removed-element subtree is not neutralized — handler onmouseover with PROOF_e59fb5bf910332a0 still live on attached subtree
Pro+ — watch recording Unlock full PoC steps
Joyent Node.js 资源管理错误漏洞
n/a / n/a
Success marker: VULNERABLE: ReDoS confirmed — moment 2.19.2 took 13085ms parsing crafted date string (threshold 3000ms breached); exfiltrated token PROOF_7bae80237e75b81a
Pro+ — watch recording Unlock full PoC steps
Jitbit Software Helpdesk 安全特征问题漏洞
n/a / n/a
Success marker: VULNERABLE: Jitbit Helpdesk PRNG shared secret recovered via SecretBuster: FOUND seed=2147483640 code=C26CBQ27DYEA44CX7WRV; planted secret (retrieved): PROOF_5e789f39cf8aba09
Pro+ — watch recording Unlock full PoC steps
CVE-2017-9841 超危
PHPUnit 安全漏洞
n/a / n/a
Success marker: VULNERABLE: PROOF_81955fd373f20cae exfiltrated by evaluating HTTP POST body in eval-stdin.php (RCE, PHPUnit 5.6.2)
Pro+ — watch recording Unlock full PoC steps
Codiad 安全漏洞
n/a / n/a
Success marker: VULNERABLE: RCE confirmed - proof token PROOF_a0f348cbf3549081 exfiltrated through webshell
Pro+ — watch recording Unlock full PoC steps
bootstrap-select 跨站脚本漏洞
n/a / n/a
Success marker: VULNERABLE: rendered <title>PROOF_9f9a78204dae3bc1</title> — unescaped HTML in an OPTION attribute (data-content) executed JavaScript via onerror
Pro+ — watch recording Unlock full PoC steps
Arbitrary File Read via Prompt Tag Source Validation Bypass in mlflow/mlflow
Success marker: VULNERABLE: arbitrary file /flag.txt read via model-version get-artifact endpoint; exfiltrated token: PROOF_7e3b4e19afd4f3e8
Pro+ — watch recording Unlock full PoC steps
Swiper has a Prototype Pollution Vulnerability
Success marker: VULNERABLE: Object.prototype polluted - ({}).canary = PROOF_37738df0ad76c4ef - proof token exfiltrated through the exploit
Pro+ — watch recording Unlock full PoC steps

16

CVE-2025-32432 Critical CVSS 10.0
Craft CMS Allows Remote Code Execution
Success marker: VULNERABLE: RCE confirmed - proof token PROOF_f0daf6ebecf83f07 exfiltrated to /exploit_out.txt
Pro+ — watch recording Unlock full PoC steps
CVE-2025-1302 Critical CVSS 9.8
JSONPath Plus 安全漏洞
Success marker: VULNERABLE: RCE confirmed — child_process.execSync ran in container and exfiltrated flag: PROOF_5e63b17e7183b57f
Pro+ — watch recording Unlock full PoC steps
CVE-2025-5277 Critical CVSS 9.6
aws-mcp-server 安全漏洞
Success marker: VULNERABLE: PROOF_3d16000354fecc8b exfiltrated through aws_cli_pipeline (command injection via sh -c stage)
Pro+ — watch recording Unlock full PoC steps
CVE-2023-43641 High CVSS 8.8
libcue vulnerable to out-of-bounds array access
Success marker: VULNERABLE: SIGSEGV, exit code 139 - OOB array access in track_set_index (CVE-2023-43641)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-22812 High CVSS 8.8
OpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution
Success marker: VULNERABLE: unauthenticated POST /pty executed the shell command; proof token exfiltrated to attacker path: PROOF_0ce890b04ead2829
Pro+ — watch recording Unlock full PoC steps
CVE-2026-55526 High CVSS 8.5
PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-79655 High CVSS 7.8
Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write
Success marker: VULNERABLE: arbitrary file write via unvalidated symlink in sos clean tar extraction: /pwned.txt contains PROOF_4c1e3c534a898378
Pro+ — watch recording Unlock full PoC steps
CVE-2025-4330 High CVSS 7.5
Extraction filter bypass for linking outside extraction directory
Success marker: VULNERABLE: PROOF_7d4495235974bcaf written to /link_here (outside extraction dir /opt/extract) via data-filter symlink bypass
Pro+ — watch recording Unlock full PoC steps
CVE-2026-55525 High CVSS 7.5
PraisonAI: SSRF via redirect-following in praisonaiagents web_crawl
Success marker: VULNERABLE: SSRF confirmed — loopback secret PROOF_c116e2386ea3c2e8 fetched through unvalidated 302 redirect by web_crawl
Pro+ — watch recording Unlock full PoC steps
CVE-2026-73086 High CVSS 7.4
nanoid: Integer Overflow or Wraparound
Pro+ — watch recording Unlock full PoC steps
CVE-2025-5252 High CVSS 7.3
PHPGurukul News Portal Project edit-subadmin.php sql injection
Success marker: VULNERABLE: time-based blind SQLi confirmed — SLEEP(5) payload: baseline 14ms vs 5015ms (delta 5001ms); DB proof token PROOF_3621497d007d68a0 reachable through the injection
Pro+ — watch recording Unlock full PoC steps
CVE-2023-7299 Medium CVSS 6.3
DataGear resolveSql sql injection
Success marker: VULNERABLE: SQL injection confirmed - attacker-controlled sql argument passed through the SQL engine and echoed back: PROOF_f4534e7fa9d33ba6
Pro+ — watch recording Unlock full PoC steps
CVE-2026-73243 Medium CVSS 5.8
kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypass
Success marker: VULNERABLE: SSRF via unauthenticated /addTask — kkFileView (kv) fetched http://attacker:8080/flag.txt; served file carries PROOF_2506e3b249844b2b
Pro+ — watch recording Unlock full PoC steps
CVE-2023-22458 Medium CVSS 5.5
Integer overflow in multiple Redis commands can lead to denial-of-service
Success marker: VULNERABLE: ZRANDMEMBER with count=-9223372036854770000 crashed redis-server: container exited, exit code 139 (SIGSEGV)
Pro+ — watch recording Unlock full PoC steps
CVE-2021-21298 Low CVSS 3.5
Path traversal in Node-Red
Success marker: VULNERABLE: path traversal via Projects API returned /flag.txt (PROOF_232e01ac3e8c8846)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-68939 Low CVSS 2.0
Pyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual)
Pro+ — watch recording Unlock full PoC steps

11

CVE-2026-63403 High CVSS 8.7
Faktory: Unrecovered panic in command handlers allows full-server denial of service
Success marker: VULNERABLE: bare QUEUE triggered handler panic (log: "E 2026-08-28T00:06:53.130Z panic handling command: runtime error: index out of range [0] with length 0: `QUEUE`"); client received "+HI {\"v\":2} +OK -ERR internal error"; proof token PR
Pro+ — watch recording Unlock full PoC steps
CVE-2026-75005 High CVSS 8.7
Apache APISIX: Unauthenticated CPU-exhaustion DoS
Success marker: VULNERABLE: single ~1.1KB GraphQL query pinned APISIX worker at 101.28%->100.54%->100.39% CPU (worker pinned at 100% of one core) for an extended period — CVE-2026-75005 CPU-exhaustion DoS confirmed
Pro+ — watch recording Unlock full PoC steps
CVE-2026-79674 High CVSS 8.2
NLTK 3.10.2 Path Traversal via corpus-reader constructors
Pro+ — watch recording Unlock full PoC steps
CVE-2026-54757 High CVSS 7.8
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
Pro+ — watch recording Unlock full PoC steps
CVE-2026-57170 High CVSS 7.8
Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)
Success marker: VULNERABLE: SSTI confirmed - trestle 4.0.3 md_clean_include re-parsed attacker markdown and executed it; proof token PROOF_4d0325fa59666230 retrieved from /poc.zip
Pro+ — watch recording Unlock full PoC steps
CVE-2026-65089 High CVSS 7.8
NVIDIA NemoClaw 命令注入漏洞
Pro+ — watch recording Unlock full PoC steps
CVE-2026-55099 High CVSS 7.5
icalendar: Algorithmic Complexity in Equality
Success marker: VULNERABLE: eq() on 20-level nested VEVENT took 3.53s (exponential O(2^depth) blowup); proof token PROOF_2bcd7fb258be9d35 exfiltrated from /flag.txt
Pro+ — watch recording Unlock full PoC steps
CVE-2026-55553 High CVSS 7.5
urllib: Cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage
Success marker: VULNERABLE: attacker origin received the x-api-key credential header (proof token PROOF_1d901c60c4bd6d76) leaked cross-origin by urllib redirect following
Pro+ — watch recording Unlock full PoC steps
CVE-2026-55620 High CVSS 7.5
eml_parser: DoS via deeply nested parens in Received headers
Success marker: VULNERABLE: ReDoS measured 1468 ms at 10000 nested parens vs 163 ms at 2500 (quadratic ~9x scaling)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-79770 High CVSS 7.5
Nokogiri before 1.19.3 ReDoS via CSS selector tokenizer
Success marker: VULNERABLE: ReDoS confirmed — adversarial CSS selector took 4911.2 ms (threshold 2000ms); baseline 0.21 ms
Pro+ — watch recording Unlock full PoC steps
CVE-2026-68513 High CVSS 7.1
OpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collision
Success marker: VULNERABLE: SIGSEGV (exit code 139) — heap buffer overflow corrupted coalesced RGB array while decoding crafted EXR
Pro+ — watch recording Unlock full PoC steps

4

CVE-2026-71513 High CVSS 8.8
NLTK 3.10.0 through 3.10.2 Remote Code Execution via AllowlistUnpickler Dotted-Name Bypass
Success marker: VULNERABLE: RCE via malicious TransitionParser model — os.system ran during model load: PROOF_994959cc2e9e7e10 uid=0(root) gid=0(root) groups=0(root)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-4671 High CVSS 7.5
justhtml before 1.18.0 Denial of Service via CSS Selector
Success marker: VULNERABLE: justhtml <1.18.0 CSS-selector DoS confirmed - attacker selector query burned 5033 ms CPU vs 0 ms for a benign selector on the same document (amplification 5033x)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-62243 High CVSS 7.5
Netty 4.2.0 through 4.2.16 TLS Hostname Verification Bypass
Pro+ — watch recording Unlock full PoC steps
CVE-2026-62384 High CVSS 7.5
NLTK FramenetCorpusReader Symlink Sandbox Bypass before 3.10.2
Pro+ — watch recording Unlock full PoC steps

3

CVE-2026-62388 High CVSS 7.5
NLTK before 3.10.0 Insecure Default Configuration in pathsec.py
Pro+ — watch recording Unlock full PoC steps
CVE-2026-63312 High CVSS 7.5
NLTK StreamBackedCorpusView Bypasses pathsec.ENFORCE Arbitrary File Read
Pro+ — watch recording Unlock full PoC steps
CVE-2026-63310 High CVSS 7.1
NLTK before 3.9.3 Missing Post-Download Integrity Verification
Pro+ — watch recording Unlock full PoC steps

2

CVE-2026-77755 High CVSS 8.7
Denial of Service in MISP-STIX Import via Malformed or Oversized STIX Documents in misp-stix library
Pro+ — watch recording Unlock full PoC steps
CVE-2026-22681 High CVSS 8.5
OpenViking < 0.3.4 SSRF via /api/v1/resources
Pro+ — watch recording Unlock full PoC steps

4

CVE-2026-76833 High CVSS 7.8
@cgauge/yaml npm Package Arbitrary Code Execution via eval() YAML Tag
Success marker: VULNERABLE: uid=0(root) gid=0(root) groups=0(root) | --- | PROOF_8047eb0e83c5e4fa
Pro+ — watch recording Unlock full PoC steps
CVE-2026-76760 High CVSS 7.3
chenhg5 cc-connect webhook.go authenticate code injection
Success marker: VULNERABLE: unauthenticated remote code injection via POST /hook "exec" — ran as uid=0(root); exfiltrated PROOF_933d3cef5f38245c
Pro+ — watch recording Unlock full PoC steps
CVE-2026-76761 High CVSS 7.3
chenhg5 cc-connect Management API engine.go shellExecCommand os command injection
Success marker: VULNERABLE: os command injection via Management API exec arg -> shellExecCommand; observed: uid=0(root) gid=0(root) groups=0(root); exfiltrated PROOF_0199d0d0fd2bffaf
Pro+ — watch recording Unlock full PoC steps
CVE-2026-76762 High CVSS 7.3
code-projects Assessment Management welcome.php sql injection
Success marker: VULNERABLE: SQL injection in /welcome.php (userid) - exfiltrated secret row: PROOF_0eceda291ddb28b1 :: user=webapp@localhost :: ver=10.11.18-MariaDB-0+deb12u1
Pro+ — watch recording Unlock full PoC steps

2

CVE-2026-49283 High CVSS 8.7
SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass
Pro+ — watch recording Unlock full PoC steps
CVE-2026-41424 High CVSS 8.2
Wazuh: Privilege Escalation via Admin-Protection Bypass in update-user API Endpoint
Pro+ — watch recording Unlock full PoC steps

6

CVE-2026-50187 High CVSS 8.8
Oh My Zsh: Arbitrary Code Execution in oh-my-zsh dotenv plugin via malicious .env files
Success marker: VULNERABLE: commands from malicious .env executed on cd via dotenv plugin; exfiltrated PROOF_4c684357b4cdb9b0 as uid=0(root) gid=0(root) groups=0(root)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-55839 High CVSS 8.7
Kestra: Stored XSS via custom Markdown [[link]] attribute injection
Success marker: VULNERABLE: stored XSS confirmed — injected onmouseover handler executed in the victim page context and exfiltrated secret PROOF_b206e25fd33150a4
Pro+ — watch recording Unlock full PoC steps
CVE-2026-75898 High CVSS 8.5
RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component
Pro+ — watch recording Unlock full PoC steps
CVE-2026-75915 High CVSS 7.5
CodeWhale before 0.8.64 Environment Variable Leak via js_execution
Pro+ — watch recording Unlock full PoC steps
CVE-2026-48798 High CVSS 7.1
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
Pro+ — watch recording Unlock full PoC steps
CVE-2026-73073 High CVSS 7.1
Vim: Arbitrary Ex Command Execution in C Omni-Completion
vim / vim
Pro+ — watch recording Unlock full PoC steps

7

CVE-2026-74997 High CVSS 8.8
Roundcube Webmail 命令注入漏洞
Pro+ — watch recording Unlock full PoC steps
CVE-2026-19693 High CVSS 8.1
extract-zip arbitrary file write outside the destination directory via a symlink at the final path component
Pro+ — watch recording Unlock full PoC steps
CVE-2026-64868 High CVSS 7.5
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging
Pro+ — watch recording Unlock full PoC steps
CVE-2026-73646 High CVSS 7.5
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
Success marker: VULNERABLE: sourceMappingURL traversal read /secret/app-secret.map and disclosed its sourcesContent (PROOF_052c20c92c70e3b5) through result.map
Pro+ — watch recording Unlock full PoC steps
CVE-2025-27770 High CVSS 7.4
UpTrain vulnerable to Remote code execution at `/create_project`
Pro+ — watch recording Unlock full PoC steps
CVE-2025-27771 High CVSS 7.4
Uptrain vulnerable to remote code execution via `/add_prompts` endpoint
Pro+ — watch recording Unlock full PoC steps
CVE-2025-27772 High CVSS 7.4
Uptrain vulnerable to remote code execution via `/new_run` endpoint
Success marker: VULNERABLE: RCE via eval() in /new_run — executed in container: uid=0(root) gid=0(root) groups=0(root) PROOF_49a15cef330d05ba
Pro+ — watch recording Unlock full PoC steps

3

CVE-2026-74792 High CVSS 7.5
Scriban before 7.0.0 Stack Overflow via nested array initializers
Pro+ — watch recording Unlock full PoC steps
CVE-2026-74794 High CVSS 7.5
Scriban before 6.6.0 Denial of Service via Infinite Recursion
Pro+ — watch recording Unlock full PoC steps
CVE-2026-74795 High CVSS 7.5
Scriban before 6.6.0 Denial of Service via Uncontrolled Recursion
Success marker: VULNERABLE: uncatchable StackOverflowException killed the .NET process parsing deeply nested template (exit code 134) - DoS confirmed
Pro+ — watch recording Unlock full PoC steps

1

CVE-2026-19825 High CVSS 7.3
SourceCodester Simple Client Management System Master.php save_service sql injection
Pro+ — watch recording Unlock full PoC steps

3

CVE-2026-49857 High CVSS 7.4
auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback
Pro+ — watch recording Unlock full PoC steps
CVE-2026-19710 High CVSS 7.3
SourceCodester Simple Student Information System view_department.php sql injection
Success marker: VULNERABLE: UNION-based SQLi in ID param exfiltrated secret token PROOF_3e1e4f26d31ee85f from flag_secrets table via view_department.php
Pro+ — watch recording Unlock full PoC steps
CVE-2026-73670 High CVSS 7.2
CMS Admin SQL Injection via db_data.php table_name Parameter
Pro+ — watch recording Unlock full PoC steps

4

CVE-2026-73284 High CVSS 8.8
RustFS: AddServiceAccount Handler Allows Creation of Root-Parent Service Accounts
Success marker: VULNERABLE: Root-parent SA created (parentUser=rustfsadmin), token=PROOF_2ccfe81dc4336898, admin API access confirmed (is_owner escalation)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-73286 High CVSS 8.1
RustF: Request headers can populate server-derived IAM condition keys, letting a caller satisfy identity-based policy conditions
Success marker: VULNERABLE: injected "userid" header satisfied IAM policy condition key aws:userid, retrieved PROOF_cdadfa484aaa26c9
Pro+ — watch recording Unlock full PoC steps
CVE-2026-73289 High CVSS 8.1
RustFS: ForAllValues/ForAnyValue negated string conditions are transposed, inverting IAM and bucket-policy decisions
Pro+ — watch recording Unlock full PoC steps
CVE-2024-47075 Medium CVSS 6.4
DOM Clobbering gadgets found in layui that lead to Cross-site Scripting
Pro+ — watch recording Unlock full PoC steps

3

CVE-2026-67180 High CVSS 8.4
Google Turbinia arbitrary command execution
Success marker: VULNERABLE: execute_container joined attacker evidence path into sh -c script; RCE as uid=0(root) worker, exfiltrated uid=0 gid=0 groups=0 PROOF_545813134524ec53
Pro+ — watch recording Unlock full PoC steps
CVE-2026-73076 High CVSS 8.4
Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.vim`
vim / vim
Success marker: VULNERABLE: arbitrary Ex command replayed via .VimballRecord in vimball#RmVimball (sil! exe exestring); :! ran as uid=0 and exfiltrated: PROOF_cf79187882034417
Pro+ — watch recording Unlock full PoC steps
CVE-2026-72922 High CVSS 8.2
AutoGPT: Webhook provider path confusion bypasses generic webhook secret verification
Pro+ — watch recording Unlock full PoC steps

6

CVE-2026-72591 High CVSS 7.7
Koito - Authenticated Server-Side Request Forgery via Album Image URL Parameter
Success marker: VULNERABLE: Koito server performed SSRF to attacker URL; observed inbound request: HEAD /PROOF_5b9ea403fad7d51b
Pro+ — watch recording Unlock full PoC steps
CVE-2026-72594 High CVSS 7.6
lobehub lobe-chat - Stored Cross-Site Scripting via Unrestricted SVG Avatar Upload
Pro+ — watch recording Unlock full PoC steps
CVE-2026-72688 High CVSS 7.5
OpenSignLabs opensignserver - Missing Authentication for Critical Function
Success marker: VULNERABLE: unauthenticated fileupload minted a MASTER_KEY-signed token; exfiltrated stored document content = "PROOF_6a5883190872ac38" (HTTP 400 without token)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-72689 High CVSS 7.5
OpenSignLabs opensignserver - Broken Object Level Authorization
Pro+ — watch recording Unlock full PoC steps
CVE-2026-72691 High CVSS 7.5
OpenSignLabs opensignserver - Authentication Bypass
Pro+ — watch recording Unlock full PoC steps
CVE-2026-72692 High CVSS 7.5
OpenSignLabs opensignserver - Missing Authorization
Pro+ — watch recording Unlock full PoC steps

8

CVE-2026-48169 High CVSS 8.8
PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
Pro+ — watch recording Unlock full PoC steps
CVE-2026-67620 High CVSS 7.7
Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List
Pro+ — watch recording Unlock full PoC steps
CVE-2026-19342 High CVSS 7.3
code-projects Task Management System Login index.php improper authentication
Pro+ — watch recording Unlock full PoC steps
CVE-2026-19343 High CVSS 7.3
code-projects Task Management System AdminLogin.php sql injection
Success marker: VULNERABLE: SQLi auth bypass succeeded; retrieved secret="PROOF_b0a18f5df8f70eae" from admin dashboard via AdminLogin.php
Pro+ — watch recording Unlock full PoC steps
CVE-2026-19344 High CVSS 7.3
code-projects Task Management System comment_count_user.php sql injection
Success marker: VULNERABLE: SQLi confirmed via task_id UNION injection; exfiltrated secret=PROOF_662e7f55f9920e06
Pro+ — watch recording Unlock full PoC steps
CVE-2026-19351 High CVSS 7.3
dresende node-sql-query Request Parameter Select.js SelectQuery.build sql injection
Success marker: VULNERABLE: SQL injection via SelectQuery.build limit() leaked secret "PROOF_d039a98dc5ac5ea3" from secrets table through stacked-query injection
Pro+ — watch recording Unlock full PoC steps
CVE-2026-45808 High CVSS 7.1
OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL
Pro+ — watch recording Unlock full PoC steps
CVE-2026-58262 High CVSS 7.1
Klever-Go: PubKeysBitmap padding bits bypass the BLS signature quorum
Pro+ — watch recording Unlock full PoC steps

2

CVE-2026-52878 High CVSS 7.5
Klever-Go: Unauthenticated nil-pointer DoS in P2P transaction validation can halt the chain
Pro+ — watch recording Unlock full PoC steps
CVE-2026-19263 High CVSS 7.3
INQUIRELAB mcp-bridge-api Servers Endpoint mcp-bridge.js command injection
Success marker: VULNERABLE: command injection via POST /servers (shell:true spawn) - uid=0(root) gid=0(root) groups=0(root)|PROOF_f1dbedcfbf80fb09|END|
Pro+ — watch recording Unlock full PoC steps

3

CVE-2026-67621 High CVSS 7.6
Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints
Pro+ — watch recording Unlock full PoC steps
CVE-2026-15816 High CVSS 7.5
Dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die()
Success marker: VULNERABLE: dracut die() RCE confirmed - injected $(...) executed as uid=0, exfiltrated flag=PROOF_bd553b3beb08126a via sourced emergency hook
Pro+ — watch recording Unlock full PoC steps
CVE-2026-19196 High CVSS 7.3
SourceCodester Photo Share Website ajax.php login sql injection
Success marker: VULNERABLE: SQLi in /social/ajax.php login extracted secret PROOF_f3e8935561de4f50 via UNION SELECT (response user field)
Pro+ — watch recording Unlock full PoC steps

3

CVE-2026-19009 High CVSS 7.3
TinyAGI Message API Endpoint response.ts collectFiles file inclusion
Success marker: VULNERABLE: collectFiles file inclusion confirmed — collected ["/etc/tinyagi-secret-flag"] and exfiltrated PROOF_09005d56f705fc06
Pro+ — watch recording Unlock full PoC steps
CVE-2026-19010 High CVSS 7.3
TinyAGI Message API Endpoint index.ts processMessage authorization
Pro+ — watch recording Unlock full PoC steps
CVE-2026-19021 High CVSS 7.3
SourceCodester Computer Repair Shop Management System Master.php delete_product sql injection
Success marker: VULNERABLE: SQL injection in /classes/Master.php?f=delete_product (ID) confirmed; exfiltrated secret "PROOF_0dfba688b2a2d110" from secrets table via stacked-query INSERT
Pro+ — watch recording Unlock full PoC steps

5

CVE-2026-67623 High CVSS 8.8
Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook
Success marker: VULNERABLE: core.fsmonitor hook executed via `vibe --worktree`, exfiltrated PROOF_2cf5728b02f42298 as uid=0(root)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-71294 High CVSS 7.7
Cotonti CMS Comments Plugin PHP Object Injection via Unrestricted unserialize() in Create/Edit Actions
Pro+ — watch recording Unlock full PoC steps
CVE-2026-71292 High CVSS 7.2
Subrion CMS Admin Grid SQL Injection via Unwhitelisted ORDER BY sort Parameter
Pro+ — watch recording Unlock full PoC steps
CVE-2026-55747 Medium CVSS 6.8
PocketFlow - Path Traversal in pocketflow-coding-agent Cookbook Example File Tools
Pro+ — watch recording Unlock full PoC steps
CVE-2026-71244 Medium CVSS 6.5
Paperless-ngx - Mail Account Test Connection Leaks Stored IMAP/OAuth Credentials to Attacker-Controlled Host
Pro+ — watch recording Unlock full PoC steps

4

CVE-2026-69100 High CVSS 8.8
LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution
Success marker: VULNERABLE: GlueFactory blacklist bypassed via Eval.me -> RCE; exfiltrated /flag.txt token=PROOF_17247601e719dd2d
Pro+ — watch recording Unlock full PoC steps
CVE-2026-62927 High CVSS 8.7
Eclipse Milo 授权问题漏洞
Success marker: VULNERABLE: PROOF=PROOF_335fb0001b14285e -- denied method executed via mixed-batch bypass; AddressSpaceManager.call received the denied CallMethodRequest
Pro+ — watch recording Unlock full PoC steps
CVE-2026-69257 High CVSS 7.6
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
Success marker: VULNERABLE: PROOF_cfe3847913241f10 exfiltrated via SSRF using ::ffff:127.0.0.1 to bypass isDeniedIP() IPv4 CIDR check
Pro+ — watch recording Unlock full PoC steps

7

CVE-2026-41453 High CVSS 8.8
Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter
Success marker: VULNERABLE: blind SQLi via rotten_lead[in] HAVING clause extracted proof token "PROOF_93c3a09238b12f10" from DB (time-based SLEEP delay 2.10s also confirmed)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-69149 High CVSS 8.6
Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)
Success marker: VULNERABLE: comment-node in <noscript> serialized unescaped; re-parse creates live <script> element containing PROOF token PROOF_c84d2ade57dab39d — XSS confirmed
Pro+ — watch recording Unlock full PoC steps
CVE-2026-69088 High CVSS 8.1
Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint
Success marker: VULNERABLE: Blueprint data-default@ invoked arbitrary static method; leaked /flag.txt token=PROOF_7fd13a7ff2abcf0a via \Symfony\Component\Yaml\Yaml::parseFile
Pro+ — watch recording Unlock full PoC steps
CVE-2026-69086 High CVSS 7.7
SiYuan before v3.7.3 Path Traversal via unvalidated avID
Pro+ — watch recording Unlock full PoC steps
CVE-2026-69091 High CVSS 7.5
Admidio before 5.0.11 Authentication Bypass via forum.php
Success marker: VULNERABLE: unauthenticated GET /modules/forum.php?mode=cards leaked forum topic "SECRET-TOKEN-PROOF_e7f6dae813339284" through login-only auth bypass (PROOF_e7f6dae813339284)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-69095 High CVSS 7.5
OpenWrt luci-app-bmx7 Path Traversal via bmx7-info
Success marker: VULNERABLE: bmx7-info path traversal exfiltrated PROOF_cfd3f532ab2d0377 from /flag.txt via GET /cgi-bin/bmx7-info?../../../../flag.txt
Pro+ — watch recording Unlock full PoC steps
CVE-2026-69097 High CVSS 7.0
GitPython before 3.1.53 Config Injection via Submodule Names
Pro+ — watch recording Unlock full PoC steps

6

CVE-2026-67356 High CVSS 8.8
ArcadeDB before 26.7.3 Privilege Escalation via JavaScript Trigger
Pro+ — watch recording Unlock full PoC steps
CVE-2025-71399 High CVSS 8.6
Better Auth before 1.4.5 Path Normalization Bypass via rou3
Pro+ — watch recording Unlock full PoC steps
CVE-2026-68581 High CVSS 8.1
Vikunja 0.22.0 through 2.3.0 Authentication Bypass via Principal ID Collision
Pro+ — watch recording Unlock full PoC steps
CVE-2026-68578 High CVSS 7.5
ArcadeDB before 26.7.3 Authentication Bypass via MCP Transport
Pro+ — watch recording Unlock full PoC steps
CVE-2025-71400 High CVSS 7.1
better-auth passkey before 1.4.0 IDOR via delete-passkey
Success marker: VULNERABLE: IDOR confirmed - Alice session deleted Bob passkey (passkey-bob-1) via delete-passkey endpoint HTTP 200; Bob row gone from DB, Alice row intact
Pro+ — watch recording Unlock full PoC steps
CVE-2023-51451 Medium CVSS 4.3
SSRF in symbolicator via invalid protocol
Success marker: VULNERABLE: PROOF_90ebfafef86172b8 exfiltrated via SSRF in symbolicator API response
Pro+ — watch recording Unlock full PoC steps

1

CVE-2026-67288 High CVSS 7.5
FreeRDP before 3.29.0 Denial of Service via smartcard cache
Pro+ — watch recording Unlock full PoC steps

2

CVE-2026-3733 Medium CVSS 6.3
xuxueli xxl-job JobInfoController.java server-side request forgery
Pro+ — watch recording Unlock full PoC steps
CVE-2025-7948 Medium CVSS 4.3
jshERP updatePwd password recovery
Pro+ — watch recording Unlock full PoC steps

4

CVE-2026-67346 High CVSS 8.6
Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass
Success marker: VULNERABLE: DNS-rebinding SSRF bypassed _is_safe_url TOCTOU check and exfiltrated PROOF_b442abee7853e00a from 127.0.0.1 internal metadata service
Pro+ — watch recording Unlock full PoC steps
CVE-2026-57862 High CVSS 8.5
Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation
Pro+ — watch recording Unlock full PoC steps
CVE-2026-48710 Medium CVSS 6.5
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
Success marker: VULNERABLE: HTTP/1.1 200 OK ; body exfiltrated protected secret PROOF_beb0ada5b3193a74 via Host-header path poisoning (baseline was HTTP/1.1 403 Forbidden)
Pro+ — watch recording Unlock full PoC steps
CVE-2025-1220 Low CVSS 3.7
Null byte termination in hostnames
Pro+ — watch recording Unlock full PoC steps

1

CVE-2026-54078 High CVSS 8.7
veraPDF Validation XXE via Rich Text
Success marker: VULNERABLE: XXE reflected /flag.txt -> PROOF_aa973f88684c02ba (rich-text /RV entity expanded by DocumentBuilderFactory.newInstance() in DictionaryKeysHelper)
Pro+ — watch recording Unlock full PoC steps

5

CVE-2026-66920 High CVSS 8.2
Pivotick - Stack Exhaustion Denial of Service via Deep or Cyclic Graph Data
Success marker: VULNERABLE: RangeError: Maximum call stack size exceeded — uncontrolled recursion on deep graph data exhausted the JS call stack (client-side DoS)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-67178 High CVSS 7.8
Open Redirect in MISP Installer-Generated Apache Configuration
Success marker: VULNERABLE: open redirect confirmed — Location: https://misp.local@attacker.example/ (proof token PROOF_2711a2c27ffd4979 exfiltrated via redirect to attacker host)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-66754 Medium CVSS 5.9
Rouille 0.1.6 - 3.6.2 Reachable Assertion DoS via remove_prefix percent-encoding
Pro+ — watch recording Unlock full PoC steps
CVE-2026-66752 Medium CVSS 5.4
tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling
Pro+ — watch recording Unlock full PoC steps
CVE-2026-67181 Medium CVSS 5.4
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header
Success marker: VULNERABLE: HTTP request smuggling via Transfer-Encoding forwarding — backend received smuggled request containing PROOF_782aa5338b84aa1a after TE:chunked framing header
Pro+ — watch recording Unlock full PoC steps

6

CVE-2026-66394 High CVSS 8.7
SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass
Pro+ — watch recording Unlock full PoC steps
CVE-2026-66397 High CVSS 8.6
phpMyFAQ before 4.1.6 Path Traversal via category image deletion
Pro+ — watch recording Unlock full PoC steps
CVE-2026-66396 High CVSS 8.4
SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL
Pro+ — watch recording Unlock full PoC steps
CVE-2026-63765 High CVSS 8.2
Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation
Pro+ — watch recording Unlock full PoC steps
CVE-2026-16756 High CVSS 7.5
Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
Pro+ — watch recording Unlock full PoC steps
CVE-2026-25800 High CVSS 7.5
quinn-proto has remote memory exhaustion from unbounded out-of-order stream reassembly
Pro+ — watch recording Unlock full PoC steps

4

CVE-2026-66032 High CVSS 8.8
libssh2 Double-Free Heap Corruption via sftp_open()
Success marker: VULNERABLE: glibc tcache double-free abort in libssh2 sftp_open(): 'free(): double free detected in tcache 2' (client exit=134)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-65709 High CVSS 8.3
sysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC API
Pro+ — watch recording Unlock full PoC steps
CVE-2026-17496 High CVSS 8.1
NoteGen chat preview XSS via unsanitized AI/skill HTML rendering
Pro+ — watch recording Unlock full PoC steps
CVE-2026-63720 High CVSS 7.5
datamodel-code-generator Code Injection via Unvalidated customBasePath Schema Field
Success marker: VULNERABLE: code injection via customBasePath confirmed; exfiltrated proof token PROOF_b12baa1f9fbd0116 through the generated module import
Pro+ — watch recording Unlock full PoC steps

3

CVE-2026-48034 High CVSS 8.5
HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
Pro+ — watch recording Unlock full PoC steps
CVE-2026-48033 High CVSS 8.4
Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name
Pro+ — watch recording Unlock full PoC steps
CVE-2026-48032 High CVSS 8.3
Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers
Success marker: VULNERABLE:PROOF_390be0134c2fb8cc PRIM-1 bypassed on multi-provider role (0 violations vs 1 for single-provider)
Pro+ — watch recording Unlock full PoC steps