<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Arbitrary-File-Read — PoC Archive</title><link>https://poc.intelseclab.com/tags/arbitrary-file-read/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 31 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/arbitrary-file-read/index.xml" rel="self" type="application/rss+xml"/><item><title>Microweber CMS Unauthenticated Path Traversal → Arbitrary File Read (CVE-2026-65694)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-65694-microweber-path-traversal/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-65694-microweber-path-traversal/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-65694 (VulnCheck advisory). Status: Unpatched. Affects: Microweber CMS — ServeStaticFileContoller::serveFromUserfiles(). Tags: microweber, path-traversal, cwe-22, unauthenticated, arbitrary-file-read, laravel, query-string-override.</description><category>web</category><category>High</category><category>microweber</category><category>path-traversal</category><category>cwe-22</category><category>unauthenticated</category><category>arbitrary-file-read</category><category>laravel</category><category>query-string-override</category></item><item><title>Rails Active Storage Arbitrary File Read to RCE via libvips Unfuzzed Loaders (CVE-2026-66066)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-66066-rails-activestorage-libvips-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-66066-rails-activestorage-libvips-rce/</guid><description>Critical severity (CVSS 9.5) — web · CVE-2026-66066 (GHSA-xr9x-r78c-5hrm). Status: Weaponized. Affects: Ruby on Rails — Active Storage (image variant processing via :vips/libvips). Tags: ruby-on-rails, active-storage, libvips, arbitrary-file-read, marshal-deserialization, rce, unauthenticated, cwe-22.</description><category>web</category><category>Critical</category><category>ruby-on-rails</category><category>active-storage</category><category>libvips</category><category>arbitrary-file-read</category><category>marshal-deserialization</category><category>rce</category><category>unauthenticated</category><category>cwe-22</category></item><item><title>ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2023-38950-zkteco-biotime-path-traversal/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2023-38950-zkteco-biotime-path-traversal/</guid><description>High severity (CVSS 7.5) — web · CVE-2023-38950. Status: Weaponized (public PoC, in CISA KEV). Affects: ZKTeco BioTime (web-based time &amp; attendance / access control management platform). Tags: zkteco, biotime, path-traversal, arbitrary-file-read, cwe-22, unauthenticated, remote, iclock-api, kev.</description><category>web</category><category>High</category><category>zkteco</category><category>biotime</category><category>path-traversal</category><category>arbitrary-file-read</category><category>cwe-22</category><category>unauthenticated</category><category>remote</category><category>iclock-api</category><category>kev</category></item><item><title>Gladinet CentreStack / Triofox Hardcoded AES Key Access-Ticket Forgery to Arbitrary File Read (CVE-2025-14611)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14611-centrestack-triofox-file-read/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14611-centrestack-triofox-file-read/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-14611. Status: Weaponized. Affects: Gladinet CentreStack and Triofox (GladCtrl64.dll / filesvr.dn file-download handler). Tags: gladinet, centrestack, triofox, hardcoded-key, aes-256-cbc, access-ticket-forgery, arbitrary-file-read, authentication-bypass, iis-app-pool, python, cwe-798, cwe-321.</description><category>web</category><category>Critical</category><category>gladinet</category><category>centrestack</category><category>triofox</category><category>hardcoded-key</category><category>aes-256-cbc</category><category>access-ticket-forgery</category><category>arbitrary-file-read</category><category>authentication-bypass</category><category>iis-app-pool</category><category>python</category><category>cwe-798</category><category>cwe-321</category></item><item><title>Weblate Arbitrary File Read via ssh-keyscan Host Argument Injection — CVE-2026-24126</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24126-weblate-ssh-keyscan-file-read/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24126-weblate-ssh-keyscan-file-read/</guid><description>High severity (CVSS 6.5) — web · CVE-2026-24126. Status: PoC. Affects: Weblate (self-hosted translation platform). Tags: weblate, argument-injection, command-injection, ssh-keyscan, arbitrary-file-read, authenticated, python, cwe-88.</description><category>web</category><category>High</category><category>weblate</category><category>argument-injection</category><category>command-injection</category><category>ssh-keyscan</category><category>arbitrary-file-read</category><category>authenticated</category><category>python</category><category>cwe-88</category></item><item><title>Veno File Manager Path Traversal to Arbitrary File Read (CVE-2026-37066)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37066-veno-file-manager-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37066-veno-file-manager-path-traversal/</guid><description>High severity — web · CVE-2026-37066. Status: PoC. Affects: Veno File Manager Project. Tags: veno-file-manager, path-traversal, arbitrary-file-read, authenticated, superadmin, cwe-22.</description><category>web</category><category>High</category><category>veno-file-manager</category><category>path-traversal</category><category>arbitrary-file-read</category><category>authenticated</category><category>superadmin</category><category>cwe-22</category></item><item><title>Veno File Manager 4.4.9 — Authenticated Arbitrary File Read (CVE-2026-37070)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37070-veno-file-manager-file-read/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37070-veno-file-manager-file-read/</guid><description>Medium severity — web · CVE-2026-37070. Status: PoC. Affects: Veno File Manager Project. Tags: file-manager, incorrect-access-control, arbitrary-file-read, php, authenticated, veno-file-manager.</description><category>web</category><category>Medium</category><category>file-manager</category><category>incorrect-access-control</category><category>arbitrary-file-read</category><category>php</category><category>authenticated</category><category>veno-file-manager</category></item><item><title>UnPoller Path Traversal / Arbitrary File Read via file:// Password Prefix (CVE-2026-36851)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-36851-unpoller-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-36851-unpoller-path-traversal/</guid><description>High severity (CVSS 7.5) — misc · CVE-2026-36851. Status: PoC. Affects: UnPoller (unpoller/unpoller). Tags: unpoller, path-traversal, arbitrary-file-read, unifi, cwe-22, cwe-20.</description><category>misc</category><category>High</category><category>unpoller</category><category>path-traversal</category><category>arbitrary-file-read</category><category>unifi</category><category>cwe-22</category><category>cwe-20</category></item><item><title>Tandoor Recipes Authenticated Local File Disclosure via Recipe Import (CVE-2026-25964)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25964-tandoor-recipes-lfi/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25964-tandoor-recipes-lfi/</guid><description>Medium severity (CVSS 4.9) — web · CVE-2026-25964 (GHSA-6485-jr28-52xx). Status: PoC. Affects: Tandoor Recipes (self-hosted recipe manager, Django-based). Tags: path-traversal, local-file-disclosure, tandoor-recipes, django, rest-api, authenticated, cwe-22, arbitrary-file-read.</description><category>web</category><category>Medium</category><category>path-traversal</category><category>local-file-disclosure</category><category>tandoor-recipes</category><category>django</category><category>rest-api</category><category>authenticated</category><category>cwe-22</category><category>arbitrary-file-read</category></item><item><title>OpenEMR EtherFax Module Authenticated Arbitrary File Read (CVE-2026-24849)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24849-openemr-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24849-openemr-path-traversal/</guid><description>Critical severity (CVSS 6.5) — web · CVE-2026-24849. Status: PoC. Affects: OpenEMR (Fax/SMS module, EtherFax provider). Tags: openemr, path-traversal, arbitrary-file-read, cwe-22, php, healthcare, phi-exposure, authenticated.</description><category>web</category><category>Critical</category><category>openemr</category><category>path-traversal</category><category>arbitrary-file-read</category><category>cwe-22</category><category>php</category><category>healthcare</category><category>phi-exposure</category><category>authenticated</category></item><item><title>n8n Unauthenticated Arbitrary File Read to RCE Full Chain — CVE-2026-21858 + CVE-2025-68613</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21858-n8n-rce-chain/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21858-n8n-rce-chain/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-21858, CVE-2025-68613. Status: Weaponized. Affects: n8n workflow automation platform. Tags: n8n, arbitrary-file-read, jwt-forgery, sandbox-bypass, expression-injection, rce, workflow-automation.</description><category>web</category><category>Critical</category><category>n8n</category><category>arbitrary-file-read</category><category>jwt-forgery</category><category>sandbox-bypass</category><category>expression-injection</category><category>rce</category><category>workflow-automation</category></item><item><title>mcp-atlassian Path Traversal via confluence_upload_attachment (CVE-2026-27825)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27825-mcp-atlassian-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27825-mcp-atlassian-path-traversal/</guid><description>Critical severity (CVSS 9.3) — web · CVE-2026-27825 (read-side twin of GHSA-xjgw-4wvw-rgm4). Status: PoC. Affects: sooperset/mcp-atlassian MCP server. Tags: mcp, path-traversal, arbitrary-file-read, confluence, mcp-atlassian, cwe-22, unauthenticated.</description><category>web</category><category>Critical</category><category>mcp</category><category>path-traversal</category><category>arbitrary-file-read</category><category>confluence</category><category>mcp-atlassian</category><category>cwe-22</category><category>unauthenticated</category></item><item><title>LiquidJS Template Engine Path Traversal — CVE-2026-30952</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-30952-liquidjs-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-30952-liquidjs-path-traversal/</guid><description>High severity (CVSS 8.7) — misc · CVE-2026-30952 (GHSA-wmfp-5q7x-987x). Status: PoC. Affects: liquidjs npm package (LiquidJS template engine). Tags: liquidjs, path-traversal, template-engine, arbitrary-file-read, nodejs, library, ssti-adjacent.</description><category>misc</category><category>High</category><category>liquidjs</category><category>path-traversal</category><category>template-engine</category><category>arbitrary-file-read</category><category>nodejs</category><category>library</category><category>ssti-adjacent</category></item><item><title>Jenkins ClassFilter Deserialization Bypass → Arbitrary File Read — CVE-2026-53435</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-53435-jenkins-deser-file-read/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-53435-jenkins-deser-file-read/</guid><description>High severity (CVSS 9.1) — web · CVE-2026-53435 (Jenkins SECURITY-3707). Status: PoC. Affects: Jenkins (core), View configuration (config.xml) deserialization path. Tags: jenkins, deserialization, classfilter-bypass, xstream, config-xml, stapler, arbitrary-file-read, docker-lab, cwe-502.</description><category>web</category><category>High</category><category>jenkins</category><category>deserialization</category><category>classfilter-bypass</category><category>xstream</category><category>config-xml</category><category>stapler</category><category>arbitrary-file-read</category><category>docker-lab</category><category>cwe-502</category></item><item><title>InvoicePlane Unauthenticated Path Traversal in Guest Controller (CVE-2026-23491)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23491-invoiceplane-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23491-invoiceplane-path-traversal/</guid><description>Critical severity — web · CVE-2026-23491. Status: PoC. Affects: InvoicePlane. Tags: invoiceplane, path-traversal, directory-traversal, unauthenticated, information-disclosure, php, arbitrary-file-read.</description><category>web</category><category>Critical</category><category>invoiceplane</category><category>path-traversal</category><category>directory-traversal</category><category>unauthenticated</category><category>information-disclosure</category><category>php</category><category>arbitrary-file-read</category></item><item><title>HashiCorp go-getter Git Pathspec Arbitrary File Read (CVE-2026-4660)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-4660-go-getter-terraform-pathspec-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-4660-go-getter-terraform-pathspec-injection/</guid><description>High severity (CVSS 7.5) — cloud · CVE-2026-4660 / HCSEC-2026-04. Status: PoC. Affects: hashicorp/go-getter (used by Terraform, Nomad, Packer, Waypoint). Tags: terraform, go-getter, git, pathspec-injection, arbitrary-file-read, ci-cd, supply-chain, iac.</description><category>cloud</category><category>High</category><category>terraform</category><category>go-getter</category><category>git</category><category>pathspec-injection</category><category>arbitrary-file-read</category><category>ci-cd</category><category>supply-chain</category><category>iac</category></item><item><title>exiftool-vendored.js Argument Injection via Newline-Delimited Tag Names (CVE-2026-43893)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-43893-exiftool-vendored-arg-injection-file-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-43893-exiftool-vendored-arg-injection-file-write/</guid><description>High severity (CVSS 8.2) — misc · CVE-2026-43893 / GHSA-cw26-7653-2rp5. Status: PoC. Affects: exiftool-vendored (npm package, Node.js wrapper around Phil Harvey's ExifTool). Tags: exiftool, exiftool-vendored, argument-injection, arbitrary-file-write, arbitrary-file-read, nodejs, cli-wrapper, newline-injection.</description><category>misc</category><category>High</category><category>exiftool</category><category>exiftool-vendored</category><category>argument-injection</category><category>arbitrary-file-write</category><category>arbitrary-file-read</category><category>nodejs</category><category>cli-wrapper</category><category>newline-injection</category></item><item><title>Apache HTTP Server mod_rewrite/mod_setenvif/mod_proxy_fcgi ap_expr Local File Read — CVE-2026-24072</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24072-apache-httpd-ap-expr-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24072-apache-httpd-ap-expr-lpe/</guid><description>Medium severity — web · CVE-2026-24072. Status: PoC. Affects: Apache HTTP Server (httpd). Tags: apache-httpd, mod_rewrite, ap_expr, htaccess, local-privilege-escalation, arbitrary-file-read, information-disclosure, cwe-668.</description><category>web</category><category>Medium</category><category>apache-httpd</category><category>mod_rewrite</category><category>ap_expr</category><category>htaccess</category><category>local-privilege-escalation</category><category>arbitrary-file-read</category><category>information-disclosure</category><category>cwe-668</category></item><item><title>Jenkins CLI Arbitrary File Read to RCE (CVE-2024-23897)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_jenkins-cli-arbitrary-file-read-rce/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_jenkins-cli-arbitrary-file-read-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2024-23897. Status: Weaponized. Affects: Jenkins controller (CLI endpoint). Tags: arbitrary-file-read, Jenkins, CLI, credential-theft, RCE, unauthenticated, KEV.</description><category>web</category><category>Critical</category><category>arbitrary-file-read</category><category>Jenkins</category><category>CLI</category><category>credential-theft</category><category>RCE</category><category>unauthenticated</category><category>KEV</category></item></channel></rss>