Dossier
proof-of-concept
Coverage of proof-of-concept in the Nexus archive.
- Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Security researcher Yuhang Wu at depthfirst published a proof-of-concept exploit for a GitLab vulnerability that allows authenticated users to execute commands as 'git' on unpatched self-managed GitLab 18.11.3 servers. The exploit involves committing two crafted Jupyter notebooks and requesting their diff, requiring no administrator rights or victim interaction.
- Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
Cisco has patched a server-side request forgery vulnerability (CVE-2026-20230) in Unified Communications Manager, allowing unauthenticated attackers to write files and escalate to root. Proof-of-concept exploit code is now public, though Cisco's PSIRT reports no observed attacks yet.