<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>misc — PoC Archive</title><link>https://poc.intelseclab.com/pocs/misc/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/pocs/misc/index.xml" rel="self" type="application/rss+xml"/><item><title>Ghidra — Swift Demangler Arbitrary Code Execution via Shared Project Files (CVE-2026-18718)</title><link>https://poc.intelseclab.com/pocs/misc/2026-08-09_cve-2026-18718-ghidra-swift-demangler-code-execution/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-08-09_cve-2026-18718-ghidra-swift-demangler-code-execution/</guid><description>High severity (CVSS 7.5) — misc · CVE-2026-18718. Status: Patched. Affects: Ghidra (NSA reverse engineering framework), Swift Demangler analyzer. Tags: ghidra, nsa, reverse-engineering, swift, demangler, code-execution, project-file, analyzer, CWE-427, CWE-494, uncontrolled-search-path, supply-chain, research-tool, shared-project.</description><category>misc</category><category>High</category><category>ghidra</category><category>nsa</category><category>reverse-engineering</category><category>swift</category><category>demangler</category><category>code-execution</category><category>project-file</category><category>analyzer</category><category>CWE-427</category><category>CWE-494</category><category>uncontrolled-search-path</category><category>supply-chain</category><category>research-tool</category><category>shared-project</category></item><item><title>safe-expr-eval: Mitigation Library for the expr-eval Unsafe eval() RCE (CVE-2025-12735)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-06_cve-2025-12735-safe-expr-eval-mitigation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-06_cve-2025-12735-safe-expr-eval-mitigation/</guid><description>Critical severity (CVSS 9.8) — misc · CVE-2025-12735. Status: Patched. Affects: expr-eval npm package (mathematical/logical expression evaluator). Tags: expr-eval, eval-injection, arbitrary-code-execution, rce, cwe-95, javascript, typescript, npm, expression-parser, mitigation-library, drop-in-replacement.</description><category>misc</category><category>Critical</category><category>expr-eval</category><category>eval-injection</category><category>arbitrary-code-execution</category><category>rce</category><category>cwe-95</category><category>javascript</category><category>typescript</category><category>npm</category><category>expression-parser</category><category>mitigation-library</category><category>drop-in-replacement</category></item><item><title>Python tarfile `filter="data"` Bypass via PATH_MAX/realpath Confusion (CVE-2025-4517)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-06_cve-2025-4517-tarfile-filter-data-path-max-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-06_cve-2025-4517-tarfile-filter-data-path-max-bypass/</guid><description>Critical severity (CVSS 9.4) — misc · CVE-2025-4517. Status: Weaponized. Affects: Python standard library tarfile module — filter="data" / filter="tar" extraction filters (PEP 706). Tags: python, tarfile, path-traversal, sandbox-bypass, path_max, realpath, symlink, cwe-22, stdlib.</description><category>misc</category><category>Critical</category><category>python</category><category>tarfile</category><category>path-traversal</category><category>sandbox-bypass</category><category>path_max</category><category>realpath</category><category>symlink</category><category>cwe-22</category><category>stdlib</category></item><item><title>Apache Parquet-Avro Schema Deserialization RCE/SSRF — Incomplete-Fix Bypass (CVE-2025-30065)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-06_cve-2025-30065-parquet-avro-schema-deserialization-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-06_cve-2025-30065-parquet-avro-schema-deserialization-rce/</guid><description>Critical severity (CVSS 9.8) — misc · CVE-2025-30065. Status: PoC. Affects: Apache Parquet Java (parquet-avro module). Tags: rce, ssrf, unsafe-deserialization, parquet-avro, avro-schema, java-class, jvm, cwe-502, cwe-20, incomplete-fix, java.</description><category>misc</category><category>Critical</category><category>rce</category><category>ssrf</category><category>unsafe-deserialization</category><category>parquet-avro</category><category>avro-schema</category><category>java-class</category><category>jvm</category><category>cwe-502</category><category>cwe-20</category><category>incomplete-fix</category><category>java</category></item><item><title>UnPoller Path Traversal / Arbitrary File Read via file:// Password Prefix (CVE-2026-36851)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-36851-unpoller-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-36851-unpoller-path-traversal/</guid><description>High severity (CVSS 7.5) — misc · CVE-2026-36851. Status: PoC. Affects: UnPoller (unpoller/unpoller). Tags: unpoller, path-traversal, arbitrary-file-read, unifi, cwe-22, cwe-20.</description><category>misc</category><category>High</category><category>unpoller</category><category>path-traversal</category><category>arbitrary-file-read</category><category>unifi</category><category>cwe-22</category><category>cwe-20</category></item><item><title>Rapid7 Nexpose Weak Keystore Entropy Credential Decryption — CVE-2026-1814</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-1814-nexpose-keystore-decrypt/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-1814-nexpose-keystore-decrypt/</guid><description>High severity — misc · CVE-2026-1814. Status: PoC. Affects: Rapid7 Nexpose (vulnerability management platform) credential export/keystore mechanism. Tags: rapid7, nexpose, credential-disclosure, weak-keystore, pkcs12, aes-cbc, offline-decryption.</description><category>misc</category><category>High</category><category>rapid7</category><category>nexpose</category><category>credential-disclosure</category><category>weak-keystore</category><category>pkcs12</category><category>aes-cbc</category><category>offline-decryption</category></item><item><title>pypdf Circular Outline Reference Infinite-Loop DoS (CVE-2026-24688)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-24688-pypdf-outline-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-24688-pypdf-outline-dos/</guid><description>High severity — misc · CVE-2026-24688. Status: PoC. Affects: pypdf (Python PDF library). Tags: pypdf, python, denial-of-service, infinite-loop, malicious-pdf, memory-exhaustion, outline-parsing, cwe-835.</description><category>misc</category><category>High</category><category>pypdf</category><category>python</category><category>denial-of-service</category><category>infinite-loop</category><category>malicious-pdf</category><category>memory-exhaustion</category><category>outline-parsing</category><category>cwe-835</category></item><item><title>psf/black GitHub Action RCE via Insecure Regex Version Validation — CVE-2026-31900</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-31900-psf-black-action-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-31900-psf-black-action-rce/</guid><description>High severity (CVSS 8.7) — misc · CVE-2026-31900 (GHSA-v53h-f6m7-xcgm). Status: PoC. Affects: psf/black GitHub Action. Tags: github-actions, supply-chain, rce, regex, pep508, ci-cd, secrets-theft, psf-black.</description><category>misc</category><category>High</category><category>github-actions</category><category>supply-chain</category><category>rce</category><category>regex</category><category>pep508</category><category>ci-cd</category><category>secrets-theft</category><category>psf-black</category></item><item><title>Orval OpenAPI Codegen Arbitrary Code Execution via Malicious Spec (CVE-2026-23947)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-23947-orval-codegen-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-23947-orval-codegen-rce/</guid><description>High severity — misc · CVE-2026-23947. Status: PoC. Affects: Orval (OpenAPI-to-TypeScript client generator), version 7.10.0. Tags: orval, openapi, code-generation, arbitrary-code-execution, nodejs, supply-chain, typescript, build-tooling.</description><category>misc</category><category>High</category><category>orval</category><category>openapi</category><category>code-generation</category><category>arbitrary-code-execution</category><category>nodejs</category><category>supply-chain</category><category>typescript</category><category>build-tooling</category></item><item><title>Ollama GGUF Heap Out-of-Bounds Read During Quantization — CVE-2026-7482</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-7482-poc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-7482-poc/</guid><description>Medium severity — misc · CVE-2026-7482. Status: PoC. Affects: Ollama (GGUF model loader / quantization pipeline). Tags: ollama, gguf, heap-overflow, out-of-bounds-read, quantization, llm-serving, docker.</description><category>misc</category><category>Medium</category><category>ollama</category><category>gguf</category><category>heap-overflow</category><category>out-of-bounds-read</category><category>quantization</category><category>llm-serving</category><category>docker</category></item><item><title>npm `tar` Package Unicode-Normalization Race Condition / File Collision (CVE-2026-2395)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-2395-tar-race-condition/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-2395-tar-race-condition/</guid><description>Medium severity — misc · CVE-2026-2395. Status: PoC. Affects: tar npm package. Tags: tar, nodejs, npm, race-condition, unicode-normalization, file-collision, archive-extraction, data-corruption.</description><category>misc</category><category>Medium</category><category>tar</category><category>nodejs</category><category>npm</category><category>race-condition</category><category>unicode-normalization</category><category>file-collision</category><category>archive-extraction</category><category>data-corruption</category></item><item><title>Node.js `tar` Package Symlink Path Traversal — CVE-2026-29786</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-29786-node-tar-symlink-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-29786-node-tar-symlink-traversal/</guid><description>High severity — misc · CVE-2026-29786. Status: PoC. Affects: tar npm package (Node.js). Tags: node-tar, path-traversal, symlink, archive-extraction, arbitrary-file-write, nodejs, supply-chain.</description><category>misc</category><category>High</category><category>node-tar</category><category>path-traversal</category><category>symlink</category><category>archive-extraction</category><category>arbitrary-file-write</category><category>nodejs</category><category>supply-chain</category></item><item><title>node-tar Hardlink/Symlink Path Traversal Arbitrary File Overwrite (CVE-2026-23745)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-23745-node-tar-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-23745-node-tar-path-traversal/</guid><description>High severity — misc · CVE-2026-23745 / GHSA-8qq5-rm4j-mr97. Status: PoC. Affects: node-tar (npm package tar). Tags: node-tar, path-traversal, arbitrary-file-overwrite, hardlink, symlink, supply-chain, nodejs, tar-archive.</description><category>misc</category><category>High</category><category>node-tar</category><category>path-traversal</category><category>arbitrary-file-overwrite</category><category>hardlink</category><category>symlink</category><category>supply-chain</category><category>nodejs</category><category>tar-archive</category></item><item><title>Netflix Conductor Unauthenticated RCE via INLINE GraalVM Evaluator — CVE-2026-58138</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-58138-conductor-unauth-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-58138-conductor-unauth-rce/</guid><description>Critical severity (CVSS 9.8) — misc · CVE-2026-58138 ([VulnCheck advisory](https://www.vulncheck.com/advisories/orkes-conductor-unauthenticated-rce-via-graalvm-script-evaluators)). Status: PoC. Affects: Conductor (OSS / Orkes workflow orchestration engine), community API. Tags: conductor, orkes, graalvm, script-evaluator, host-access, workflow-engine, unauth-rce.</description><category>misc</category><category>Critical</category><category>conductor</category><category>orkes</category><category>graalvm</category><category>script-evaluator</category><category>host-access</category><category>workflow-engine</category><category>unauth-rce</category></item><item><title>Multiparty Denial of Service via Prototype-Pollution Field Name (CVE-2026-8161)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-8161-multiparty-prototype-pollution-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-8161-multiparty-prototype-pollution-dos/</guid><description>Medium severity — misc · CVE-2026-8161 / GHSA-qxch-whhj-8956. Status: PoC. Affects: multiparty (npm package, multipart/form-data parser). Tags: multiparty, nodejs, prototype-pollution, denial-of-service, cwe-1321, uncaught-exception, multipart-parser.</description><category>misc</category><category>Medium</category><category>multiparty</category><category>nodejs</category><category>prototype-pollution</category><category>denial-of-service</category><category>cwe-1321</category><category>uncaught-exception</category><category>multipart-parser</category></item><item><title>Microsoft Semantic Kernel In-Memory Vector Store Filter eval() Sandbox Bypass RCE (CVE-2026-26030)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-26030-semantic-kernel-eval-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-26030-semantic-kernel-eval-rce/</guid><description>Critical severity — misc · CVE-2026-26030. Status: Weaponized. Affects: Microsoft Semantic Kernel (Python), InMemoryCollection vector store connector. Tags: semantic-kernel, python, eval-injection, sandbox-bypass, prompt-injection, llm-agent, rce, ast-allowlist-bypass, vector-store.</description><category>misc</category><category>Critical</category><category>semantic-kernel</category><category>python</category><category>eval-injection</category><category>sandbox-bypass</category><category>prompt-injection</category><category>llm-agent</category><category>rce</category><category>ast-allowlist-bypass</category><category>vector-store</category></item><item><title>Malicious DOCX/OLE CLSID Object Embedding Builder (CVE-2026-21509)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-21509-office-ole-docx-clsid-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-21509-office-ole-docx-clsid-rce/</guid><description>High severity — misc · CVE-2026-21509. Status: PoC. Affects: Microsoft Office (Word) OLE embedded-object handling. Tags: office, docx, ole, clsid, document-weaponization, embedded-object, python, malicious-document.</description><category>misc</category><category>High</category><category>office</category><category>docx</category><category>ole</category><category>clsid</category><category>document-weaponization</category><category>embedded-object</category><category>python</category><category>malicious-document</category></item><item><title>local-mcp exec Tool Sandbox/Restriction Bypass (CVE-2026-6130)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-6130-local-mcp-exec-sandbox-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-6130-local-mcp-exec-sandbox-bypass/</guid><description>Medium severity — misc · CVE-2026-6130. Status: PoC. Affects: local-mcp (zero-dependency MCP server for local file operations, v1.1.1). Tags: mcp, model-context-protocol, sandbox-bypass, command-execution, exec-restriction-bypass.</description><category>misc</category><category>Medium</category><category>mcp</category><category>model-context-protocol</category><category>sandbox-bypass</category><category>command-execution</category><category>exec-restriction-bypass</category></item><item><title>LiquidJS Template Engine Path Traversal — CVE-2026-30952</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-30952-liquidjs-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-30952-liquidjs-path-traversal/</guid><description>High severity (CVSS 8.7) — misc · CVE-2026-30952 (GHSA-wmfp-5q7x-987x). Status: PoC. Affects: liquidjs npm package (LiquidJS template engine). Tags: liquidjs, path-traversal, template-engine, arbitrary-file-read, nodejs, library, ssti-adjacent.</description><category>misc</category><category>High</category><category>liquidjs</category><category>path-traversal</category><category>template-engine</category><category>arbitrary-file-read</category><category>nodejs</category><category>library</category><category>ssti-adjacent</category></item><item><title>iOS App Intents Path Traversal — CVE-2026-28995</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-28995-ios-appintents-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-28995-ios-appintents-path-traversal/</guid><description>High severity — misc · CVE-2026-28995. Status: PoC. Affects: Apple App Intents framework (iOS). Tags: ios, app-intents, path-traversal, sandbox-escape, swift, file-disclosure, mobile.</description><category>misc</category><category>High</category><category>ios</category><category>app-intents</category><category>path-traversal</category><category>sandbox-escape</category><category>swift</category><category>file-disclosure</category><category>mobile</category></item><item><title>Feast Registry gRPC Unauthenticated RCE via dill.loads — CVE-2026-56121</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-56121-feast-unauth-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-56121-feast-unauth-rce/</guid><description>Critical severity (CVSS 9.8) — misc · CVE-2026-56121. Status: PoC. Affects: Feast (open-source feature store) registry gRPC server. Tags: feast, feature-store, dill, pickle, deserialization, grpc, unauth-rce, mlops.</description><category>misc</category><category>Critical</category><category>feast</category><category>feature-store</category><category>dill</category><category>pickle</category><category>deserialization</category><category>grpc</category><category>unauth-rce</category><category>mlops</category></item><item><title>exiftool-vendored.js Argument Injection via Newline-Delimited Tag Names (CVE-2026-43893)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-43893-exiftool-vendored-arg-injection-file-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-43893-exiftool-vendored-arg-injection-file-write/</guid><description>High severity (CVSS 8.2) — misc · CVE-2026-43893 / GHSA-cw26-7653-2rp5. Status: PoC. Affects: exiftool-vendored (npm package, Node.js wrapper around Phil Harvey's ExifTool). Tags: exiftool, exiftool-vendored, argument-injection, arbitrary-file-write, arbitrary-file-read, nodejs, cli-wrapper, newline-injection.</description><category>misc</category><category>High</category><category>exiftool</category><category>exiftool-vendored</category><category>argument-injection</category><category>arbitrary-file-write</category><category>arbitrary-file-read</category><category>nodejs</category><category>cli-wrapper</category><category>newline-injection</category></item><item><title>docling-core Unsafe YAML Deserialization Leading to Code Execution — CVE-2026-24009</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-24009-docling-core-yaml-deserialization/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-24009-docling-core-yaml-deserialization/</guid><description>High severity — misc · CVE-2026-24009. Status: PoC. Affects: docling-core (Python library). Tags: docling-core, yaml-deserialization, pyyaml, unsafe-loader, rce, python, cwe-502.</description><category>misc</category><category>High</category><category>docling-core</category><category>yaml-deserialization</category><category>pyyaml</category><category>unsafe-loader</category><category>rce</category><category>python</category><category>cwe-502</category></item><item><title>Claude Code WebFetch Hardcoded HuggingFace Bare-Hostname Allow-List Bypass — CVE-2026-54316</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-54316-claude-code-webfetch-hf-exfil/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-54316-claude-code-webfetch-hf-exfil/</guid><description>Medium severity — misc · CVE-2026-54316 (GHSA-fg94-h982-f3mm). Status: PoC. Affects: @anthropic-ai/claude-code (npm package, Claude Code CLI). Tags: claude-code, webfetch, prompt-injection, exfiltration, huggingface, allow-list-bypass, agentic-ai, docker-lab, cwe-183.</description><category>misc</category><category>Medium</category><category>claude-code</category><category>webfetch</category><category>prompt-injection</category><category>exfiltration</category><category>huggingface</category><category>allow-list-bypass</category><category>agentic-ai</category><category>docker-lab</category><category>cwe-183</category></item><item><title>ChatterBot Denial of Service via SQLAlchemy Connection Pool Exhaustion (CVE-2026-23842)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-23842-chatterbot-dos-pool-exhaustion/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-23842-chatterbot-dos-pool-exhaustion/</guid><description>High severity (CVSS 7.5) — misc · CVE-2026-23842. Status: PoC. Affects: ChatterBot (Python conversational AI library). Tags: chatterbot, denial-of-service, sqlalchemy, connection-pool-exhaustion, python, cwe-400, resource-exhaustion.</description><category>misc</category><category>High</category><category>chatterbot</category><category>denial-of-service</category><category>sqlalchemy</category><category>connection-pool-exhaustion</category><category>python</category><category>cwe-400</category><category>resource-exhaustion</category></item><item><title>Apktool Resource Table Path Traversal — Malicious APK Builder (CVE-2026-39973)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-39973-apktool-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-39973-apktool-path-traversal/</guid><description>High severity — misc · CVE-2026-39973. Status: PoC. Affects: iBotPeaches/Apktool (Android APK decompiler/rebuilder). Tags: apktool, path-traversal, resources-arsc, apk, decompilation, arbitrary-file-write, android-tooling.</description><category>misc</category><category>High</category><category>apktool</category><category>path-traversal</category><category>resources-arsc</category><category>apk</category><category>decompilation</category><category>arbitrary-file-write</category><category>android-tooling</category></item><item><title>AI Model-Loader `trust_remote_code` Order-of-Operations RCE Simulation (CVE-2026-22807)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-22807-vllm-trust-remote-code-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-22807-vllm-trust-remote-code-bypass/</guid><description>High severity — misc · CVE-2026-22807. Status: PoC. Affects: AI inference/model-loading frameworks that resolve custom model classes via auto_map before validating trust_remote_code (pattern seen in vLLM/Transformers-style loaders). Tags: vllm, huggingface, trust-remote-code, toctou, model-loading, supply-chain, python, code-execution.</description><category>misc</category><category>High</category><category>vllm</category><category>huggingface</category><category>trust-remote-code</category><category>toctou</category><category>model-loading</category><category>supply-chain</category><category>python</category><category>code-execution</category></item><item><title>Adobe Acrobat/Reader PDF Exploit Generator — Claimed Prototype Pollution (CVE-2026-3462)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-3462-acrobat-pdf-exploit-generator/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-3462-acrobat-pdf-exploit-generator/</guid><description>Critical severity — misc · CVE-2026-3462 (repo internally references CVE-2026-34621 — CVE-ID mismatch, see Notes). Status: Weaponized. Affects: Adobe Acrobat / Acrobat Reader (DC Continuous and 2024 Classic tracks). Tags: pdf, exploit-generator, prototype-pollution, sandbox-escape, evasion, persistence, malware-generator, farmed-repo-suspected.</description><category>misc</category><category>Critical</category><category>pdf</category><category>exploit-generator</category><category>prototype-pollution</category><category>sandbox-escape</category><category>evasion</category><category>persistence</category><category>malware-generator</category><category>farmed-repo-suspected</category></item><item><title>7-Zip RAR5 Mark-of-the-Web / ADS Full-Chain Bypass</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-03_7zip-rar5-motw-ads-bypass/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-03_7zip-rar5-motw-ads-bypass/</guid><description>High severity — misc · None assigned as of 2026-07-03. Status: PoC. Affects: 7-Zip 26.01 x64 for Windows. Tags: 7-zip, rar5, mark-of-the-web, alternate-data-streams, ntfs, motw-bypass, windows, archive-extraction.</description><category>misc</category><category>High</category><category>7-zip</category><category>rar5</category><category>mark-of-the-web</category><category>alternate-data-streams</category><category>ntfs</category><category>motw-bypass</category><category>windows</category><category>archive-extraction</category></item><item><title>WinRAR Windows Path Traversal via NTFS Alternate Data Streams (CVE-2025-8088)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-01_cve-2025-8088-winrar-ads-path-traversal/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-01_cve-2025-8088-winrar-ads-path-traversal/</guid><description>High severity (CVSS 8.4) — misc · CVE-2025-8088. Status: Weaponized. Affects: WinRAR (Windows). Tags: path-traversal, WinRAR, NTFS, Alternate-Data-Streams, RomCom, Storm-0978, persistence, startup-folder, in-the-wild.</description><category>misc</category><category>High</category><category>path-traversal</category><category>WinRAR</category><category>NTFS</category><category>Alternate-Data-Streams</category><category>RomCom</category><category>Storm-0978</category><category>persistence</category><category>startup-folder</category><category>in-the-wild</category></item><item><title>YellowKey — BitLocker Bypass via WinRE autofstx.exe (CVE-2026-45585)</title><link>https://poc.intelseclab.com/pocs/misc/2026-06-26_yellowkey-bitlocker-bypass/</link><pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-06-26_yellowkey-bitlocker-bypass/</guid><description>Medium severity (CVSS 6.1) — misc · CVE-2026-45585. Status: Researched. Affects: Windows BitLocker / WinRE (autofstx.exe). Tags: BitLocker, bypass, physical-access, WinRE, TPM, autofstx, NTFS-transactions, FsTx, Windows-11, Windows-Server-2022, zero-day, full-disk-access.</description><category>misc</category><category>Medium</category><category>BitLocker</category><category>bypass</category><category>physical-access</category><category>WinRE</category><category>TPM</category><category>autofstx</category><category>NTFS-transactions</category><category>FsTx</category><category>Windows-11</category><category>Windows-Server-2022</category><category>zero-day</category><category>full-disk-access</category></item><item><title>Apache Parquet Java Unsafe Deserialization RCE (CVE-2025-30065)</title><link>https://poc.intelseclab.com/pocs/misc/2026-05-16_apache-parquet-unsafe-deserialization-rce/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-05-16_apache-parquet-unsafe-deserialization-rce/</guid><description>Critical severity (CVSS 10) — misc · CVE-2025-30065. Status: Weaponized. Affects: Apache Parquet Java (parquet-avro) schema parsing consumers. Tags: RCE, unsafe-deserialization, parquet-avro, avro-schema, Java, JVM, SSRF, data-pipeline.</description><category>misc</category><category>Critical</category><category>RCE</category><category>unsafe-deserialization</category><category>parquet-avro</category><category>avro-schema</category><category>Java</category><category>JVM</category><category>SSRF</category><category>data-pipeline</category></item><item><title>WinRAR Archive Extraction Path Traversal (CVE-2025-6218)</title><link>https://poc.intelseclab.com/pocs/misc/2026-05-15_winrar-path-traversal-cve-2025-6218/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-05-15_winrar-path-traversal-cve-2025-6218/</guid><description>High severity — misc · CVE-2025-6218. Status: Weaponized. Affects: WinRAR archive extraction workflow. Tags: path-traversal, arbitrary-file-write, startup-folder, WinRAR, Windows, user-interaction.</description><category>misc</category><category>High</category><category>path-traversal</category><category>arbitrary-file-write</category><category>startup-folder</category><category>WinRAR</category><category>Windows</category><category>user-interaction</category></item></channel></rss>