PoC Archive PoC Archive

tag

Qx

  • CVE-2021-22205 web CRITICAL 10 KEV Ransomware EPSS 100%

    GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205)

    GitLab Workhorse intercepts multipart file uploads and strips image metadata by shelling out to ExifTool before the request is routed to Rails and therefore before any authentication or authorization decision is made. ExifTool in turn contained…

    Patched 2026-08-09