<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Express — PoC Archive</title><link>https://poc.intelseclab.com/tags/express/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/express/index.xml" rel="self" type="application/rss+xml"/><item><title>Mongoose `populate()` Match `$where` Bypass Command Injection (CVE-2025-23061)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-23061-mongoose-command-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-23061-mongoose-command-injection/</guid><description>Critical severity (CVSS 9) — web · CVE-2025-23061. Status: Weaponized. Affects: Mongoose (Node.js MongoDB ODM). Tags: mongoose, nodejs, nosql-injection, mongodb, populate, where-operator, command-injection, rce, cwe-943, cwe-94, express.</description><category>web</category><category>Critical</category><category>mongoose</category><category>nodejs</category><category>nosql-injection</category><category>mongodb</category><category>populate</category><category>where-operator</category><category>command-injection</category><category>rce</category><category>cwe-943</category><category>cwe-94</category><category>express</category></item><item><title>Sequelize ORM JSON Cast SQL Injection — CVE-2026-30951</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30951-sequelize-json-cast-sqli/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30951-sequelize-json-cast-sqli/</guid><description>High severity — web · CVE-2026-30951. Status: PoC. Affects: Sequelize ORM v6 (Node.js). Tags: sequelize, sqli, orm, json-cast, nodejs, express, sqlite, boolean-based.</description><category>web</category><category>High</category><category>sequelize</category><category>sqli</category><category>orm</category><category>json-cast</category><category>nodejs</category><category>express</category><category>sqlite</category><category>boolean-based</category></item><item><title>Node.js protobufjs Dynamic Type Compilation RCE (CVE-2026-41242)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-41242-protobufjs-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-41242-protobufjs-rce/</guid><description>Critical severity — web · CVE-2026-41242. Status: PoC. Affects: Node.js application using protobufjs (Root.fromJSON + dynamic decode). Tags: nodejs, protobufjs, rce, deserialization, express, code-injection, javascript.</description><category>web</category><category>Critical</category><category>nodejs</category><category>protobufjs</category><category>rce</category><category>deserialization</category><category>express</category><category>code-injection</category><category>javascript</category></item><item><title>Multer Orphaned Temporary File Disk-Exhaustion DoS — CVE-2026-3304</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3304-multer-orphaned-file-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3304-multer-orphaned-file-dos/</guid><description>High severity (CVSS 8.7) — web · CVE-2026-3304. Status: PoC. Affects: Multer (Node.js multipart/form-data middleware for Express). Tags: multer, nodejs, express, dos, file-upload, orphaned-file, disk-exhaustion, multipart.</description><category>web</category><category>High</category><category>multer</category><category>nodejs</category><category>express</category><category>dos</category><category>file-upload</category><category>orphaned-file</category><category>disk-exhaustion</category><category>multipart</category></item><item><title>Handlebars AST Injection Remote Code Execution — CVE-2026-33937</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33937-handlebars-ast-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33937-handlebars-ast-rce/</guid><description>Critical severity — web · CVE-2026-33937. Status: PoC. Affects: Handlebars (Node.js templating engine). Tags: handlebars, rce, template-injection, ast-injection, nodejs, express, javascript-compiler, code-generation.</description><category>web</category><category>Critical</category><category>handlebars</category><category>rce</category><category>template-injection</category><category>ast-injection</category><category>nodejs</category><category>express</category><category>javascript-compiler</category><category>code-generation</category></item></channel></rss>