PoC Archive PoC Archive

tag

Argument-Injection

High
Weblate Arbitrary File Read via ssh-keyscan Host Argument Injection — CVE-2026-24126
CVE-2026-24126· Weblate (self-hosted translation platform) patched
High
Prefect GitRepository Git Argument Injection RCE via `commit_sha` — CVE-2026-5366
CVE-2026-5366 (Huntr bounty e2e88a0f-a8f6-49c9-94c5-e98dc385f07a)· Prefect (workflow orchestration platform), GitRepository storage class patched
High
Pardus Software Center Local Privilege Escalation via APT Option Injection (CVE-2026-14459 / CVE-2026-14460)
CVE-2026-14459 (also covers CVE-2026-14460)· pardus-software (Pardus Software Center) patched
Not disclosed
Fireshare Unauthenticated Arbitrary File Write/Overwrite — CVE-2026-54337
CVE-2026-54337 (see [GHSA-hmh2-6g84-q8jx](https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-hmh2-6g84-q8jx))· Fireshare (self-hosted video sharing app), <= 1.16.3 unpatched
High
exiftool-vendored.js Argument Injection via Newline-Delimited Tag Names (CVE-2026-43893)
CVE-2026-43893 / GHSA-cw26-7653-2rp5· exiftool-vendored (npm package, Node.js wrapper around Phil Harvey's ExifTool) patched
Critical
Cockpit Unauthenticated Remote Code Execution via SSH Argument Injection (CVE-2026-4631)
CVE-2026-4631 (GHSA-m4gv-x78h-3427)· Cockpit (Linux web-based server admin console) patched