<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Redis — PoC Archive</title><link>https://poc.intelseclab.com/tags/redis/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/redis/index.xml" rel="self" type="application/rss+xml"/><item><title>RediShell: Redis Lua Scripting Use-After-Free Leading to JOP-Chained Remote Code Execution (CVE-2025-49844)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-49844-redis-lua-uaf-jop-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-49844-redis-lua-uaf-jop-rce/</guid><description>Critical severity (CVSS 9.9) — binary · CVE-2025-49844. Status: Weaponized. Affects: Redis (embedded Lua scripting engine). Tags: redis, lua, use-after-free, uaf, memory-corruption, jop, jump-oriented-programming, shellcode, iced-x86, docker, cwe-416, rce.</description><category>binary</category><category>Critical</category><category>redis</category><category>lua</category><category>use-after-free</category><category>uaf</category><category>memory-corruption</category><category>jop</category><category>jump-oriented-programming</category><category>shellcode</category><category>iced-x86</category><category>docker</category><category>cwe-416</category><category>rce</category></item><item><title>Mercator Configuration SSRF Chained to Internal Redis RCE (CVE-2026-49345)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49345-mercator-ssrf-redis-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49345-mercator-ssrf-redis-rce/</guid><description>Critical severity — web · CVE-2026-49345. Status: PoC. Affects: Mercator (sourcentis/mercator vulnerability-management web app), ConfigurationController::testProvider. Tags: ssrf, redis, rce, gopher, webshell, internal-network-pivot, php, mercator.</description><category>web</category><category>Critical</category><category>ssrf</category><category>redis</category><category>rce</category><category>gopher</category><category>webshell</category><category>internal-network-pivot</category><category>php</category><category>mercator</category></item><item><title>AutoGPT Platform Chat Session IDOR / Session Hijack — CVE-2026-30950</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30950-autogpt-session-idor/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30950-autogpt-session-idor/</guid><description>High severity (CVSS 7.1) — web · CVE-2026-30950 (GHSA-q58p-v9r9-7gqj). Status: PoC. Affects: AutoGPT Platform (autogpt-platform-backend, chat/copilot feature). Tags: autogpt, idor, cwe-862, session-hijack, missing-authorization, python, fastapi, redis.</description><category>web</category><category>High</category><category>autogpt</category><category>idor</category><category>cwe-862</category><category>session-hijack</category><category>missing-authorization</category><category>python</category><category>fastapi</category><category>redis</category></item><item><title>Redis Vector Set Duplicate HNSW Node ID RCE</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_redis-vector-set-hnsw-id-rce/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_redis-vector-set-hnsw-id-rce/</guid><description>Critical severity — network · None assigned as of 2026-07-03. Status: Weaponized. Affects: Redis server, Vector Set module (modules/vector-sets). Tags: redis, vector-set, hnsw, rce, deserialization, use-after-free, heap-corruption, rdb-restore.</description><category>network</category><category>Critical</category><category>redis</category><category>vector-set</category><category>hnsw</category><category>rce</category><category>deserialization</category><category>use-after-free</category><category>heap-corruption</category><category>rdb-restore</category></item><item><title>TossUp — TerraMaster TOS Unauthenticated Redis Root RCE + NFS LPE</title><link>https://poc.intelseclab.com/pocs/network/2026-05-18_tossup-terramaster-redis-rce/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-18_tossup-terramaster-redis-rce/</guid><description>Critical severity — network · N/A (vendor confirmed TOS4 is EOL; no fix planned). Status: Weaponized. Affects: TerraMaster TOS3_A1.0 4.2.41, Redis 4.0.10. Tags: RCE, unauthenticated, Redis, TerraMaster, NAS, AArch64, root, module-loading, replication-abuse, NFS, no_root_squash, LPE, network.</description><category>network</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>Redis</category><category>TerraMaster</category><category>NAS</category><category>AArch64</category><category>root</category><category>module-loading</category><category>replication-abuse</category><category>NFS</category><category>no_root_squash</category><category>LPE</category><category>network</category></item></channel></rss>