<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Code-Injection — PoC Archive</title><link>https://poc.intelseclab.com/tags/code-injection/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 31 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/code-injection/index.xml" rel="self" type="application/rss+xml"/><item><title>IBM Langflow OSS Unauthenticated RCE via Auto-Login + validate/code Chain (CVE-2026-9198)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-9198-langflow-auto-login-validate-code-rce/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-9198-langflow-auto-login-validate-code-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-9198. Status: Weaponized. Affects: IBM Langflow OSS (visual AI/agent-flow builder). Tags: langflow, ibm, auto-login, code-injection, cwe-94, unauthenticated, rce, python-exec, ai-agent-framework.</description><category>web</category><category>Critical</category><category>langflow</category><category>ibm</category><category>auto-login</category><category>code-injection</category><category>cwe-94</category><category>unauthenticated</category><category>rce</category><category>python-exec</category><category>ai-agent-framework</category></item><item><title>XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-24893-xwiki-solrsearch-groovy-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-24893-xwiki-solrsearch-groovy-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-24893. Status: Weaponized. Affects: XWiki (SolrSearch macro, Main.SolrSearch). Tags: xwiki, groovy, rce, unauthenticated, cwe-94, code-injection, reverse-shell, python, wiki.</description><category>web</category><category>Critical</category><category>xwiki</category><category>groovy</category><category>rce</category><category>unauthenticated</category><category>cwe-94</category><category>code-injection</category><category>reverse-shell</category><category>python</category><category>wiki</category></item><item><title>pgAdmin 4 Query Tool Authenticated eval() RCE (CVE-2025-2945)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-2945-pgadmin-eval-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-2945-pgadmin-eval-rce/</guid><description>Critical severity (CVSS 9.9) — web · CVE-2025-2945. Status: Weaponized. Affects: pgAdmin 4 (web-based PostgreSQL administration tool). Tags: pgadmin, postgresql, rce, eval-injection, code-injection, cwe-95, python, authenticated, sqleditor.</description><category>web</category><category>Critical</category><category>pgadmin</category><category>postgresql</category><category>rce</category><category>eval-injection</category><category>code-injection</category><category>cwe-95</category><category>python</category><category>authenticated</category><category>sqleditor</category></item><item><title>Shopware Twig Rendered-View Code Injection Regression (CVE-2026-23498)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23498-shopware-twig-code-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23498-shopware-twig-code-injection/</guid><description>High severity — web · CVE-2026-23498. Status: PoC. Affects: Shopware (shopware/shopware, shopware/core). Tags: shopware, twig, code-injection, ssti, php, cwe-94, regression, template-sandbox-bypass.</description><category>web</category><category>High</category><category>shopware</category><category>twig</category><category>code-injection</category><category>ssti</category><category>php</category><category>cwe-94</category><category>regression</category><category>template-sandbox-bypass</category></item><item><title>PbootCMS Authenticated RCE via sitecopyright Field (CVE-2026-36239)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-36239-pbootcms-authenticated-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-36239-pbootcms-authenticated-rce/</guid><description>Critical severity — web · CVE-2026-36239. Status: Weaponized. Affects: PbootCMS. Tags: pbootcms, rce, authenticated, code-injection, template-injection, cwe-94.</description><category>web</category><category>Critical</category><category>pbootcms</category><category>rce</category><category>authenticated</category><category>code-injection</category><category>template-injection</category><category>cwe-94</category></item><item><title>OpenWebUI "Tools" Unsandboxed exec() Remote Code Execution — CVE-2026-0766</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0766-openwebui-tool-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0766-openwebui-tool-rce/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-0766 (ZDI-26-032, GHSA-cggw-334c-f4mj). Status: Weaponized. Affects: OpenWebUI (self-hosted LLM web interface). Tags: openwebui, llm, code-injection, exec, tool-creation, cwe-94, rce, authenticated.</description><category>web</category><category>High</category><category>openwebui</category><category>llm</category><category>code-injection</category><category>exec</category><category>tool-creation</category><category>cwe-94</category><category>rce</category><category>authenticated</category></item><item><title>Node.js protobufjs Dynamic Type Compilation RCE (CVE-2026-41242)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-41242-protobufjs-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-41242-protobufjs-rce/</guid><description>Critical severity — web · CVE-2026-41242. Status: PoC. Affects: Node.js application using protobufjs (Root.fromJSON + dynamic decode). Tags: nodejs, protobufjs, rce, deserialization, express, code-injection, javascript.</description><category>web</category><category>Critical</category><category>nodejs</category><category>protobufjs</category><category>rce</category><category>deserialization</category><category>express</category><category>code-injection</category><category>javascript</category></item><item><title>DbGate Unauthenticated RCE via JSON Script Runner (CVE-2026-47668)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-47668-dbgate-json-script-runner-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-47668-dbgate-json-script-runner-rce/</guid><description>Critical severity (CVSS 3.1) — web · CVE-2026-47668. Status: PoC. Affects: DbGate (dbgate-serve — web-based database management tool). Tags: dbgate, rce, code-injection, javascript-injection, cwe-94, cwe-20, cwe-1188, database-management.</description><category>web</category><category>Critical</category><category>dbgate</category><category>rce</category><category>code-injection</category><category>javascript-injection</category><category>cwe-94</category><category>cwe-20</category><category>cwe-1188</category><category>database-management</category></item><item><title>DbGate `loadReader` `functionName` Injection RCE (CVE-2026-48017)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48017-dbgate-loadreader-functionname-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48017-dbgate-loadreader-functionname-rce/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-48017 / GHSA-hv83-ggc4-v385. Status: PoC. Affects: DbGate (dbgate-api), a web-based database management GUI. Tags: dbgate, nodejs, code-injection, rce, cwe-94, authenticated, database-gui.</description><category>web</category><category>High</category><category>dbgate</category><category>nodejs</category><category>code-injection</category><category>rce</category><category>cwe-94</category><category>authenticated</category><category>database-gui</category></item><item><title>Apache NiFi 2.8.0 — EXECUTE_CODE Permission Bypass to Groovy RCE (CVE-2026-39816)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39816-apache-nifi-groovy-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39816-apache-nifi-groovy-rce/</guid><description>Critical severity — web · CVE-2026-39816. Status: Weaponized. Affects: Apache NiFi (with the optional graph bundle / nifi-other-graph-services-nar). Tags: apache-nifi, groovy, code-injection, privilege-escalation, rce, graph-bundle, authenticated.</description><category>web</category><category>Critical</category><category>apache-nifi</category><category>groovy</category><category>code-injection</category><category>privilege-escalation</category><category>rce</category><category>graph-bundle</category><category>authenticated</category></item></channel></rss>