<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cross-Origin — PoC Archive</title><link>https://poc.intelseclab.com/tags/cross-origin/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/cross-origin/index.xml" rel="self" type="application/rss+xml"/><item><title>WebKit WebGPU `importExternalTexture` Cross-Origin Video Frame Leak (CVE-2026-43700)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-43700-webgpu-importexternaltexture-cross-origin-leak/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-43700-webgpu-importexternaltexture-cross-origin-leak/</guid><description>High severity — web · CVE-2026-43700. Status: PoC. Affects: WebKit / Safari (GPUDevice.importExternalTexture WebGPU API). Tags: webkit, safari, webgpu, cross-origin, information-disclosure, same-origin-policy-bypass, external-texture, video.</description><category>web</category><category>High</category><category>webkit</category><category>safari</category><category>webgpu</category><category>cross-origin</category><category>information-disclosure</category><category>same-origin-policy-bypass</category><category>external-texture</category><category>video</category></item><item><title>WebKit Navigation API `NavigateEvent.sourceElement` Cross-Origin DOM Leak (CVE-2026-43735)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-43735-webkit-navigateevent-sourceelement-leak/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-43735-webkit-navigateevent-sourceelement-leak/</guid><description>High severity — web · CVE-2026-43735. Status: PoC. Affects: WebKit / Safari (Navigation API — NavigateEvent.sourceElement). Tags: webkit, safari, navigation-api, navigateevent, cross-origin, information-disclosure, dom-access, same-origin-policy-bypass, iframe.</description><category>web</category><category>High</category><category>webkit</category><category>safari</category><category>navigation-api</category><category>navigateevent</category><category>cross-origin</category><category>information-disclosure</category><category>dom-access</category><category>same-origin-policy-bypass</category><category>iframe</category></item><item><title>Sliver C2 MCP Server Unauthenticated CORS/Preflight Bypass (CVE-2026-34227)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34227-sliver-mcp-cors-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34227-sliver-mcp-cors-bypass/</guid><description>High severity — web · CVE-2026-34227 (GHSA-6fpf-248c-m7wm). Status: PoC. Affects: Sliver C2 framework — MCP (Model Context Protocol) server interface. Tags: sliver, c2, mcp, cors, csrf, sse, cross-origin, data-exfiltration.</description><category>web</category><category>High</category><category>sliver</category><category>c2</category><category>mcp</category><category>cors</category><category>csrf</category><category>sse</category><category>cross-origin</category><category>data-exfiltration</category></item><item><title>Realtime Collaboration Platform — CORS Misconfiguration Leading to Authenticated Data Exposure (CVE-2026-27579)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27579-cors-misconfig-data-exposure/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27579-cors-misconfig-data-exposure/</guid><description>High severity (CVSS 7.4) — web · CVE-2026-27579 (GHSA-qh5m-p8jh-hx88). Status: PoC. Affects: realtime-collaboration-platform (karnop), backed by Appwrite. Tags: cors, misconfiguration, appwrite, cross-origin, credentials, data-exposure, session-hijack, javascript.</description><category>web</category><category>High</category><category>cors</category><category>misconfiguration</category><category>appwrite</category><category>cross-origin</category><category>credentials</category><category>data-exposure</category><category>session-hijack</category><category>javascript</category></item></channel></rss>