PoC Archive PoC Archive

tag

Integrity-Bypass

  • CVE-2026-49230 web CRITICAL 9.1

    Apache APISIX `jwe-decrypt` Integrity-Check Bypass → Unauthenticated Gateway Auth Bypass (CVE-2026-49230)

    The jwe-decrypt plugin is an auth-type APISIX plugin that decrypts an incoming JWE token with a per-consumer AES-256-GCM secret and forwards the plaintext upstream as proof of authentication. Its internal helper jwedecryptwithobj() returns only the decrypted…

    Patched 2026-07-27
  • CVE-2026-7574 binary HIGH 8.7

    Claude Desktop Cowork VM Image Integrity Bypass / Local Persistence (CVE-2026-7574)

    CVE-2026-7574 is a VM image integrity bypass in Anthropic's Claude Desktop Cowork feature (macOS). Before booting the Cowork virtual machine, the application validates only the presence of rootfs.img and its associated version marker (.rootfs.img.origin); it…

    Unverified 2026-06-30