PoC Archive PoC Archive

tag

Supply-Chain

Ghidra — Swift Demangler Arbitrary Code Execution via Shared Project Files (CVE-2026-18718)
CVE-2026-18718 misc Patched
CVE-2026-18718miscHIGH 7.5Patched2026-08-09tj-actions/branch-names GitHub Actions Command Injection (CVE-2025-54416)
CVE-2025-54416 cloud Patched
CVE-2025-54416cloudCRITICAL 9.1Patched2026-07-06Supply Chain Command Injection in AWS CDK's NodejsFunction — CVE-2026-11417
CVE-2026-11417 cloud Patched
CVE-2026-11417cloudHIGH 3.1Patched2026-07-05Sherlock CI `pull_request_target` Command Injection → GitHub Actions Secret Exfiltration (CVE-2026-44590)
CVE-2026-44590 cloud Patched
CVE-2026-44590cloudCRITICAL 9.3Patched2026-07-05psf/black GitHub Action RCE via Insecure Regex Version Validation — CVE-2026-31900
CVE-2026-31900 (GHSA-v53h-f6m7-xcgm) misc Patched
CVE-2026-31900miscHIGH 8.7Patched2026-07-05Prefect GitRepository Git Argument Injection RCE via `commit_sha` — CVE-2026-5366
CVE-2026-5366 (Huntr bounty e2e88a0f-a8f6-49c9-94c5-e98dc385f07a) web Patched
CVE-2026-5366webHIGHPatched2026-07-05Orval OpenAPI Codegen Arbitrary Code Execution via Malicious Spec (CVE-2026-23947)
CVE-2026-23947 misc Patched
CVE-2026-23947miscHIGHPatched2026-07-05Node.js `tar` Package Symlink Path Traversal — CVE-2026-29786
CVE-2026-29786 misc Patched
CVE-2026-29786miscHIGHPatched2026-07-05node-tar Hardlink/Symlink Path Traversal Arbitrary File Overwrite (CVE-2026-23745)
CVE-2026-23745 / GHSA-8qq5-rm4j-mr97 misc Patched
CVE-2026-23745 / GHSA-8qq5-rm4j-mr97miscHIGHPatched2026-07-05Next.js Vendored picomatch Vulnerable Dependency — CVE-2026-33671
CVE-2026-33671 web Patched
CVE-2026-33671webHIGHPatched2026-07-05HashiCorp go-getter Git Pathspec Arbitrary File Read (CVE-2026-4660)
CVE-2026-4660 / HCSEC-2026-04 cloud Patched
CVE-2026-4660 / HCSEC-2026-04cloudHIGH 7.5Patched2026-07-05AI Model-Loader `trust_remote_code` Order-of-Operations RCE Simulation (CVE-2026-22807)
CVE-2026-22807 misc Patched
CVE-2026-22807miscHIGHPatched2026-07-05