PoC Archive PoC Archive

tag

Search-Path-Hijack

  • CVE-2026-0776 binary HIGH 7.3

    Discord Desktop Client Uncontrolled Search Path Element / Local Code Execution (CVE-2026-0776)

    CVE-2026-0776 is an Uncontrolled Search Path Element (CWE-427) issue in the Discord Desktop Client on Windows: under certain conditions the Electron/Node.js runtime resolves and loads native/JS modules from a filesystem location that a local, unprivileged…

    Unverified 2026-07-05
  • None assigned as of 2026-07-03 binary HIGH

    ImageMagick Ghostscript Delegate Search Path Hijack

    When ImageMagick converts PDF/PS/EPS-family inputs on Windows and cannot resolve a full path to Ghostscript, it falls back to invoking the bare executable name gswin64c.exe and launches it through the Windows process API with the application name left unset —…

    Unverified 2026-07-03