PoC Archive PoC Archive

tag

Shell

  • CVE-2025-32463 binary CRITICAL 9.3 KEV EPSS 56%

    Sudo `chroot` Option Local Privilege Escalation (CVE-2025-32463)

    Sudo's -R/--chroot option allowed an unprivileged local user to make sudo chroot() into a directory the user controls before sudo resolves and loads NSS (Name Service Switch) configuration and modules. Because sudo continues to consult /etc/nsswitch.conf and…

    Patched 2026-07-06
  • CVE-2025-54309 web CRITICAL 9 KEV EPSS 94%

    CrushFTP AS2 Header Authentication Bypass (CVE-2025-54309)

    CrushFTP's web interface trusts the presence of the HTTP headers X-DMZ-Proxy: disabled and X-AS2-Version: 1.0 (plus a matching User-Agent) as proof that a request originates from an already-authenticated AS2 (Applicability Statement 2 / EDI-over-HTTP) proxy…

    Patched 2026-07-06
  • CVE-2026-7574 binary HIGH 8.7

    Claude Desktop Cowork VM Image Integrity Bypass / Local Persistence (CVE-2026-7574)

    CVE-2026-7574 is a VM image integrity bypass in Anthropic's Claude Desktop Cowork feature (macOS). Before booting the Cowork virtual machine, the application validates only the presence of rootfs.img and its associated version marker (.rootfs.img.origin); it…

    Unverified 2026-06-30