PoC Archive PoC Archive

tag

Symlink

Node.js Permission Model Symlink Escape (CVE-2025-55130)
CVE-2025-55130 binary Unverified
CVE-2025-55130binaryCRITICAL 9.1Unverified2026-09-03Docker — CopyEscape: Container-to-Host Escape via docker cp Race Condition (CVE-2026-17106)
CVE-2026-17106 binary Unverified
CVE-2026-17106binaryCRITICAL 9.8Unverified2026-08-15Windows Defender — ShieldBreak: RoguePlanet (CVE-2026-50656) Patch Bypass via Cloud Files Rehydration + Object Manager Symlinks EPSS 11%
Bypass of CVE-2026-50656 (RoguePlanet); no CVE assigned to ShieldBreak as of 2026-08-11 binary Unpatched
Bypass of CVE-2026-50656binaryHIGH 7.8Unpatched2026-08-11Python tarfile `filter="data"` Bypass via PATH_MAX/realpath Confusion (CVE-2025-4517)
CVE-2025-4517 misc Patched
CVE-2025-4517miscCRITICAL 9.4Patched2026-07-06Node.js `tar` Package Symlink Path Traversal — CVE-2026-29786
CVE-2026-29786 misc Patched
CVE-2026-29786miscHIGHPatched2026-07-05node-tar Hardlink/Symlink Path Traversal Arbitrary File Overwrite (CVE-2026-23745)
CVE-2026-23745 / GHSA-8qq5-rm4j-mr97 misc Patched
CVE-2026-23745 / GHSA-8qq5-rm4j-mr97miscHIGHPatched2026-07-05LiteSpeed cPanel/WHM Plugin Symlink Privilege Escalation — CVE-2026-54420 KEV
CVE-2026-54420 network Unverified
CVE-2026-54420networkHIGH 8.5Unverified2026-07-05CVE-2026-50656 RoguePlanet — Safe Vulnerability Checker (Resurface) EPSS 11%
CVE-2026-50656 binary Patched
CVE-2026-50656binaryHIGH 7.8Patched2026-06-26LiteSpeed User-End cPanel Plugin Local Privilege Escalation (CVE-2026-48172) KEV EPSS 19%
CVE-2026-48172 web Unverified
CVE-2026-48172webHIGHUnverified2026-05-30