PoC Archive PoC Archive

tag

Client-Side

  • CVE-2026-41653 web CRITICAL

    BentoPDF Stored XSS to File Exfiltration (CVE-2026-41653)

    BentoPDF's Markdown-to-PDF tool renders user-supplied Markdown through markdown-it with html: true enabled and injects the resulting HTML directly into the DOM via innerHTML, with no sanitizer (e.g. DOMPurify) in between. A crafted .md file containing an <img…

    Patched 2026-07-05
  • None assigned as of 2026-07-03 network HIGH

    OpenVPN Connect Server-Pushed Option Current-User Command Execution

    A malicious OpenVPN server can push an echo option to a connected OpenVPN Connect for Windows client that decodes into the internal script.win.user.disconnect script key. OpenVPN Connect then executes that pushed command when the client disconnects, even…

    Unverified 2026-07-03