PoC Archive PoC Archive

tag

Supply-Chain

Critical
tj-actions/branch-names GitHub Actions Command Injection (CVE-2025-54416)
CVE-2025-54416· tj-actions/branch-names GitHub Action patched
High
Supply Chain Command Injection in AWS CDK's NodejsFunction — CVE-2026-11417
CVE-2026-11417· aws-cdk-lib (npm package), NodejsFunction L2 construct patched
Critical
Sherlock CI `pull_request_target` Command Injection → GitHub Actions Secret Exfiltration (CVE-2026-44590)
CVE-2026-44590· sherlock-project/sherlock (GitHub Actions workflow validate_modified_targets.yml) patched
High
psf/black GitHub Action RCE via Insecure Regex Version Validation — CVE-2026-31900
CVE-2026-31900 (GHSA-v53h-f6m7-xcgm)· psf/black GitHub Action patched
High
Prefect GitRepository Git Argument Injection RCE via `commit_sha` — CVE-2026-5366
CVE-2026-5366 (Huntr bounty e2e88a0f-a8f6-49c9-94c5-e98dc385f07a)· Prefect (workflow orchestration platform), GitRepository storage class patched
High
Orval OpenAPI Codegen Arbitrary Code Execution via Malicious Spec (CVE-2026-23947)
CVE-2026-23947· Orval (OpenAPI-to-TypeScript client generator), version 7.10.0 patched
High
Node.js `tar` Package Symlink Path Traversal — CVE-2026-29786
CVE-2026-29786· tar npm package (Node.js) unpatched
High
node-tar Hardlink/Symlink Path Traversal Arbitrary File Overwrite (CVE-2026-23745)
CVE-2026-23745 / GHSA-8qq5-rm4j-mr97· node-tar (npm package tar) patched
High
Next.js Vendored picomatch Vulnerable Dependency — CVE-2026-33671
CVE-2026-33671· Next.js 16.2.4 (bundles picomatch 4.0.3 at node_modules/next/dist/compiled/picomatch/) patched
High
HashiCorp go-getter Git Pathspec Arbitrary File Read (CVE-2026-4660)
CVE-2026-4660 / HCSEC-2026-04· hashicorp/go-getter (used by Terraform, Nomad, Packer, Waypoint) patched
High
AI Model-Loader `trust_remote_code` Order-of-Operations RCE Simulation (CVE-2026-22807)
CVE-2026-22807· AI inference/model-loading frameworks that resolve custom model classes via auto_map before validating trust_remote_code (pattern seen in vLLM/Transformers-style loaders) unpatched