r0hanSH/exploits

Exploits

★ 0Forks 0GitHub ↗Compare

README

exploits

Proof-of-concept write-ups for vulnerabilities I have reported in open-source projects.

Bug bounty submissions, client engagements and undisclosed research are not published here, per disclosure policy.

26 entries across 21 products.

2026

Product Popularity ID Vulnerability Severity
 authentik goauthentik/authentik stars CVE-2026-94609 Privilege escalation (CWE-269) via mass-assignable Group.parents and Group.roles High
 backstage backstage/backstage stars CWE-94 Code injection (CWE-94) via the allowlisted extra_templates and theme.custom_dir MkDocs keys in TechDocs High
 sentry getsentry/sentry stars CWE-1236 CSV / formula injection (CWE-1236) in the issue-tag and data-export CSV writers Low
 gitea go-gitea/gitea stars CVE-2026-73535 2FA bypass and persistent account takeover via OpenID identity linking High
 portainer portainer/portainer stars CVE-2026-72533 Docker API proxy authorization bypass via a non-canonical API version prefix Critical
 strapi strapi/strapi stars CWE-79 XSS Stored XSS via Media Library file upload High
 strapi strapi/strapi stars CWE-918 SSRF SSRF in Media Library URL upload High

2023

Product Popularity ID Vulnerability Severity
 apache-airflow apache/airflow stars CVE-2023-29247 Stored XSS Medium
nivo plouc/nivo stars CWE-79 XSS XSS Medium
three.js mrdoob/three.js stars three weekly downloads CWE-79 XSS XSS Low
 mastodon mastodon/mastodon stars CWE-641 Improper Restriction of Names for Files and Other Resources Medium

2022

Product Popularity ID Vulnerability Severity
 slidev slidevjs/slidev stars CWE-79 XSS CSS injection and limited XSS (CWE-79) via postMessage Medium
fullpage.js alvarotrigo/fullpage.js stars CVE-2022-1295 Prototype pollution Critical
url-parse url-parse weekly downloads CVE-2022-0686 URL parsing issue Critical
 grav getgrav/grav stars CVE-2022-0268 XSS Medium
 grav getgrav/grav stars CVE-2022-0743 XSS Medium
 karma karma-runner/karma stars karma weekly downloads CVE-2022-0437 DOM-based XSS Medium
parse-path parse-path weekly downloads CVE-2022-0624 Authorization Bypass Through User-Controlled Key via URL parsing confusion High
 mastodon mastodon/mastodon stars CVE-2022-0432 Prototype Pollution Medium
reveal.js hakimel/reveal.js stars CVE-2022-0776 XSS Medium
 URI.js medialize/uri.js stars urijs weekly downloads CVE-2022-0613 URL parsing issue Medium
 apache-superset apache/superset stars CVE-2022-43718 XSS Medium
 apache-superset apache/superset stars CVE-2022-45438 Information Leak Medium
 apache-superset apache/superset stars CVE-2022-41703 SQL Injection Medium

2021

Product Popularity ID Vulnerability Severity
 firefox - CVE-2021-4221 Address bar spoofing on Firefox for Android via RTL characters Medium

2020

Product Popularity ID Vulnerability Severity
 macos-server - CVE-2020-9995 URL parsing issue in Profile Manager leading to open redirect or cross-site scripting Medium

Contributors

r0hanSH

Issues