PoC Archive PoC Archive

tag

Electron

  • CVE-2026-22804 web HIGH

    Termix Stored XSS via Malicious SVG Upload -> LFI / Session Hijack (CVE-2026-22804 / GHSA-m3cv-5hgp-hv35)

    Termix's built-in File Manager renders SVG files opened from a connected host using dangerouslySetInnerHTML, without stripping active content such as <foreignObject>/<img onerror=...>. An attacker who can place a crafted SVG on a filesystem reachable via…

    Patched 2026-07-05
  • CVE-2026-0776 binary HIGH 7.3

    Discord Desktop Client Uncontrolled Search Path Element / Local Code Execution (CVE-2026-0776)

    CVE-2026-0776 is an Uncontrolled Search Path Element (CWE-427) issue in the Discord Desktop Client on Windows: under certain conditions the Electron/Node.js runtime resolves and loads native/JS modules from a filesystem location that a local, unprivileged…

    Unverified 2026-07-05
  • None assigned as of 2026-07-03 binary CRITICAL 3.1

    Lunar Client Modrinth Explore Raw-HTML to Local Launcher Execution Chain

    The chain begins with Lunar Client's Explore feature rendering attacker-controlled Modrinth project Markdown (project body and version changelog) through ReactMarkdown with the rehypeRaw plugin and no observed HTML sanitizer, allowing raw HTML/script-capable…

    Unverified 2026-07-03