<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Argument-Injection — PoC Archive</title><link>https://poc.intelseclab.com/tags/argument-injection/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/argument-injection/index.xml" rel="self" type="application/rss+xml"/><item><title>Cisco IMC Argument Injection to Root RCE (CVE-2026-20200)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-20200-cisco-imc-argument-injection-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-20200-cisco-imc-argument-injection-rce/</guid><description>Critical severity (CVSS 9.9) — network · CVE-2026-20200 / NSIDE-SA-2026-003. Status: Patched. Affects: Cisco Integrated Management Controller (CIMC). Tags: cisco, imc, cimc, argument-injection, rce, redfish, curl, reverse-shell, arm, file-read, file-write, CVE-2026-20200.</description><category>network</category><category>Critical</category><category>cisco</category><category>imc</category><category>cimc</category><category>argument-injection</category><category>rce</category><category>redfish</category><category>curl</category><category>reverse-shell</category><category>arm</category><category>file-read</category><category>file-write</category><category>CVE-2026-20200</category></item><item><title>Weblate Arbitrary File Read via ssh-keyscan Host Argument Injection — CVE-2026-24126</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24126-weblate-ssh-keyscan-file-read/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24126-weblate-ssh-keyscan-file-read/</guid><description>High severity (CVSS 6.5) — web · CVE-2026-24126. Status: PoC. Affects: Weblate (self-hosted translation platform). Tags: weblate, argument-injection, command-injection, ssh-keyscan, arbitrary-file-read, authenticated, python, cwe-88.</description><category>web</category><category>High</category><category>weblate</category><category>argument-injection</category><category>command-injection</category><category>ssh-keyscan</category><category>arbitrary-file-read</category><category>authenticated</category><category>python</category><category>cwe-88</category></item><item><title>Prefect GitRepository Git Argument Injection RCE via `commit_sha` — CVE-2026-5366</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5366-prefect-git-argument-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5366-prefect-git-argument-injection/</guid><description>High severity — web · CVE-2026-5366 (Huntr bounty e2e88a0f-a8f6-49c9-94c5-e98dc385f07a). Status: PoC. Affects: Prefect (workflow orchestration platform), GitRepository storage class. Tags: prefect, git, argument-injection, rce, upload-pack, workflow-orchestration, supply-chain, python.</description><category>web</category><category>High</category><category>prefect</category><category>git</category><category>argument-injection</category><category>rce</category><category>upload-pack</category><category>workflow-orchestration</category><category>supply-chain</category><category>python</category></item><item><title>Pardus Software Center Local Privilege Escalation via APT Option Injection (CVE-2026-14459 / CVE-2026-14460)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-14459-pardus-software-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-14459-pardus-software-lpe/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-14459 (also covers CVE-2026-14460). Status: Weaponized. Affects: pardus-software (Pardus Software Center). Tags: linux, pardus, privilege-escalation, polkit, pkexec, apt-injection, argument-injection, local-dos.</description><category>binary</category><category>High</category><category>linux</category><category>pardus</category><category>privilege-escalation</category><category>polkit</category><category>pkexec</category><category>apt-injection</category><category>argument-injection</category><category>local-dos</category></item><item><title>Fireshare Unauthenticated Arbitrary File Write/Overwrite — CVE-2026-54337</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54337-fireshare-file-overwrite/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54337-fireshare-file-overwrite/</guid><description>Info severity — web · CVE-2026-54337 (see [GHSA-hmh2-6g84-q8jx](https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-hmh2-6g84-q8jx)). Status: PoC. Affects: Fireshare (self-hosted video sharing app), &lt;= 1.16.3. Tags: fireshare, unauthenticated, arbitrary-file-write, argument-injection, ffmpeg, file-upload, cwe-73, docker.</description><category>web</category><category>Info</category><category>fireshare</category><category>unauthenticated</category><category>arbitrary-file-write</category><category>argument-injection</category><category>ffmpeg</category><category>file-upload</category><category>cwe-73</category><category>docker</category></item><item><title>exiftool-vendored.js Argument Injection via Newline-Delimited Tag Names (CVE-2026-43893)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-43893-exiftool-vendored-arg-injection-file-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-43893-exiftool-vendored-arg-injection-file-write/</guid><description>High severity (CVSS 8.2) — misc · CVE-2026-43893 / GHSA-cw26-7653-2rp5. Status: PoC. Affects: exiftool-vendored (npm package, Node.js wrapper around Phil Harvey's ExifTool). Tags: exiftool, exiftool-vendored, argument-injection, arbitrary-file-write, arbitrary-file-read, nodejs, cli-wrapper, newline-injection.</description><category>misc</category><category>High</category><category>exiftool</category><category>exiftool-vendored</category><category>argument-injection</category><category>arbitrary-file-write</category><category>arbitrary-file-read</category><category>nodejs</category><category>cli-wrapper</category><category>newline-injection</category></item><item><title>Cockpit Unauthenticated Remote Code Execution via SSH Argument Injection (CVE-2026-4631)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4631-cockpit-ssh-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4631-cockpit-ssh-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-4631 (GHSA-m4gv-x78h-3427). Status: PoC. Affects: Cockpit (Linux web-based server admin console). Tags: cockpit, ssh, command-injection, argument-injection, cwe-78, unauthenticated-rce, proxycommand.</description><category>web</category><category>Critical</category><category>cockpit</category><category>ssh</category><category>command-injection</category><category>argument-injection</category><category>cwe-78</category><category>unauthenticated-rce</category><category>proxycommand</category></item></channel></rss>