PoC Archive PoC Archive

tag

Drive-By

  • CVE-2026-34200 web CRITICAL 9.6

    Nhost Local MCP Server Unauthenticated CORS Bypass Leading to Full Project Takeover (CVE-2026-34200)

    The Nhost CLI's local MCP server, used to let AI agents/tools manage a developer's Nhost project, has no inbound authentication and inherits a permissive Access-Control-Allow-Origin: CORS policy from the underlying mcp-go library. Because the server does not…

    Patched 2026-07-05
  • CVE-2026-2441 web HIGH 8.8 KEV EPSS 22%

    Chrome CSSFontFeatureValuesMap Use-After-Free (CVE-2026-2441)

    CVE-2026-2441 is a Blink use-after-free vulnerability in CSSFontFeatureValuesMap iteration logic. A crafted web page mutates a styleset map while iterating through entries, which can invalidate internal structures and trigger renderer memory safety failure on…

    Unpatched 2026-05-16