PoC Archive PoC Archive

tag

Jwt-Forgery

Not disclosed (unauthenticated path traversal leading to full admin JWT forgery)
Nezha Dashboard Path Traversal → JWT Secret Leak → Token Forgery — CVE-2026-53519
CVE-2026-53519 (GHSA-5c25-7vpj-9mqh)· Nezha Dashboard (monitoring/agent management panel) unpatched
Critical
n8n Unauthenticated Arbitrary File Read to RCE Full Chain — CVE-2026-21858 + CVE-2025-68613
CVE-2026-21858, CVE-2025-68613· n8n workflow automation platform patched
Critical
HAXcms Node.js Private Key Disclosure via Broken HMAC (CVE-2026-46395)
CVE-2026-46395· HAXcms Node.js backend (elmsln/HAXcms, haxcms-nodejs) — src/lib/HAXCMS.js patched