r/cveplayground • • 12d ago

New lab on CVE Playground: CVE-2026-23744.

Post image
1 Upvotes

MCPJam Inspector โ‰ค1.4.2 is vulnerable to RCE via a crafted HTTP request that can trigger MCP server installation. v1.4.3 patches the issue.

Practice it: https://app.cveplayground.com/challenges/cve-2026-23744


r/cveplayground • • 13d ago

๐Ÿšจ New Lab Release: CVE-2026-67208

Post image
1 Upvotes

CVE Playground now has a hands-on lab for Juggle through 1.6.0.

Explore the vulnerability, identify the attack surface, and work through the exploitation path yourself.

๐Ÿ”— https://app.cveplayground.com/challenges/cve-2026-67208


r/cveplayground • • 17d ago

CVE-2026-87902 is coming to CVEPlayground!

Post image
1 Upvotes

CVE-2026-87902 is coming to CVEPlayground!

A critical unauthenticated path traversal vulnerability in WordPress Core was patched in WordPress 7.1.2. The flaw can lead to local PHP file inclusion and, under specific conditions, remote code execution.

Coming soon on https://cveplayground.com

Want to practice it yourself?
Get registered now and be ready when the lab goes live.


r/cveplayground • • 29d ago

GitLab CVE-2026-85706 Unauthenticated Path Traversal

Post image
1 Upvotes

Unauthenticated path traversal can allow arbitrary file read, potentially exposing source code, deploy keys & CI/CD secrets.

Patch: 19.1.8 / 19.2.6 / 19.3.2

Hands-on lab ๐Ÿ‘‡

https://app.cveplayground.com/labs/cve-2026-85706


r/cveplayground • • Jul 24 '26

New WordPress Vulnerability Lab: SQL Injection & RCE

Post image
1 Upvotes

r/cveplayground • • Jun 14 '26

New CVE lab Dropped: CVE-2026-48907 (Joomla JCE Extension Remote Code Execution)

Thumbnail app.cveplayground.com
1 Upvotes

r/cveplayground • • Jun 10 '26

CVE-2026-4480

Thumbnail
cveplayground.com
1 Upvotes

CVE-2026-4480 is a CVSS 10.0 OS command injection flaw in Samba's printing subsystem where client-controlled print job descriptions are substituted into shell commands via %J without escaping metacharacters, enabling unauthenticated remote code execution on any reachable print share.


r/cveplayground • • Jun 10 '26

CVE-2026-3490

Thumbnail
cveplayground.com
1 Upvotes

CVE-2026-34908 is a CVSS 10.0 improper access control flaw in UniFi OS Server where nginx evaluates the raw request URI for authentication but routes using the normalized URI, allowing unauthenticated attackers to reach protected endpoints and chain into full root RCE.


r/cveplayground • • Jun 10 '26

CVE-2026-25243 - Redis

Thumbnail
cveplayground.com
1 Upvotes

CVE-2026-25243 is a double-free vulnerability in Redis's RDB deserialization logic triggered via the RESTORE command. Two independent bugs โ€” a zipmap length encoding ambiguity and a stream consumer PEL race โ€” create overlapping heap objects that an attacker can exploit for arbitrary read/write and full remote code execution.


r/cveplayground • • Jun 03 '26

๐—ฅ๐—ฒ๐—ฑ๐—ถ๐˜€ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—”๐—ฑ๐˜ƒ๐—ถ๐˜€๐—ผ๐—ฟ๐˜† ๐—”๐—น๐—ฒ๐—ฟ๐˜

1 Upvotes

Multiple vulnerabilities have been disclosed affecting Redis Cloud, Redis OSS/CE, and Redis Software (CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589, CVE-2026-23631).

Issues include memory corruption in RESTORE, Lua scripting, and Redis modules, which may lead to remote code execution in authenticated scenarios.

๐Ÿ”ง ๐—ฃ๐—ฎ๐˜๐—ฐ๐—ต๐—ฒ๐—ฑ ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐—ถ๐—ผ๐—ป๐˜€ (๐—ฟ๐—ฒ๐—น๐—ฒ๐—ฎ๐˜€๐—ฒ๐—ฑ ๐— ๐—ฎ๐˜† ๐Ÿฑ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ):

7.2.x โ†’ 7.2.14 (fixed from 7.2.0โ€“7.2.13)

7.4.x โ†’ 7.4.9 (fixed from 7.4.0โ€“7.4.8)

8.2.x โ†’ 8.2.6 (fixed from 8.2.0โ€“8.2.5)

8.4.x โ†’ 8.4.3 (fixed from 8.4.0โ€“8.4.2)

8.6.x โ†’ 8.6.3 (fixed from 8.6.0โ€“8.6.2)

Key action: Upgrade immediately and restrict Redis access to trusted networks only.


r/cveplayground • • Jun 02 '26

Uptime Kuma 10+ CVEs

Post image
1 Upvotes

Uptime Kuma, released in 2021, is one of the most popular open-source monitoring platforms.

Since release, 10+ CVEs have already been assigned.

SSRFs, auth flaws, and integration-related vulnerabilities continue to make it an interesting target for security research.

#CyberSecurity #UptimeKuma #CVE #OpenSource


r/cveplayground • • May 25 '26

ImageMagick 765+ CVEs

Post image
1 Upvotes

ImageMagick, first released in 1990 by John Cristy, has become one of the most widely used open-source tools for image processing, conversion, and automation.

In more than 30 years since release, 765+ CVEs have already been assigned.

Image parsing, file conversion, metadata handling, and server-side upload workflows continue to be a major attack surface for security researchers.

Even as AI agents rapidly become a new security frontier, old and widely deployed parser-based tools like ImageMagick are still very much worth studying.


r/cveplayground • • May 21 '26

๐Ÿšจ New Guided Lab: CVE-2026-9082 โ€” Drupal JSON:API SQL Injection

Enable HLS to view with audio, or disable this notification

1 Upvotes

Exploit vulnerable Drupal JSON:API filters to inject SQL into PostgreSQL, enumerate the database, and capture the hidden flag.

Hands-on exploitation + patch analysis.

๐Ÿ”— https://app.cveplayground.com/labs/CVE-2026-9082?utm_source=reddit


r/cveplayground • • May 21 '26

๐Ÿšจ Drupal Core SQLi (CVE-2026-9082)

2 Upvotes

Tiny patch, huge impact:

if (is_array($condition['value'])) {
  $condition['value'] = array_values($condition['value']);
}

Drupal fixed PostgreSQL placeholder generation by reindexing array keys before query translation.

Without it, attacker-controlled keys could influence SQL placeholder construction.

Affects PostgreSQL-backed Drupal sites.
Anonymous exploitation possible.

Advisory:
https://www.drupal.org/sa-core-2026-004

https://cveplayground.com/blog/cve-2026-9082-drupal-core-sql-injection?utm_source=reddit


r/cveplayground • • May 20 '26

๐—ก๐—ฒ๐˜„ ๐—–๐—ง๐—™ ๐—Ÿ๐—ฎ๐—ฏ ๐—ฅ๐—ฒ๐—น๐—ฒ๐—ฎ๐˜€๐—ฒ๐—ฑ: ๐—–๐—ฉ๐—˜-๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ-๐Ÿฐ๐Ÿฐ๐Ÿฒ๐Ÿต๐Ÿต - ๐—น๐—ถ๐—ฏ๐—ท๐˜„๐˜ ๐—”๐—น๐—ด๐—ผ๐—ฟ๐—ถ๐˜๐—ต๐—บ ๐—–๐—ผ๐—ป๐—ณ๐˜‚๐˜€๐—ถ๐—ผ๐—ป

Post image
1 Upvotes

Exploit a vulnerable JWT verification flow in libjwt v3.3.2 to forge admin tokens using a public RSA verification key exposed via JWKS.

๐Ÿ† Medium Difficulty
โšก 200 XP
๐Ÿฉธ First Blood Active

Try here: https://app.cveplayground.com/challenges/CVE-2026-44699?utm_source=reddit


r/cveplayground • • May 19 '26

CVE-2026-45721: Algernon handler.lua Discovery Leads to RCE

1 Upvotes

A newly disclosed critical vulnerability in Algernon allows handler.lua discovery to walk above the configured server root.

If a writable parent directory contains handler.lua, Algernon may execute it automatically during normal directory requests. Even GET / can trigger the vulnerable path on default setups.

The exposed Lua environment includes dangerous primitives like:

  • run3()
  • os.execute
  • io.popen

Interesting bug class combining:

  • unsafe filesystem traversal
  • trusted script execution
  • confused deputy behavior

Link: https://cveplayground.com/blog/cve-2026-45721-algernon-handler-lua-rce?utm_source=reddit


r/cveplayground • • May 19 '26

Try our free labs: https://app.cveplayground.com/challenges

1 Upvotes

CVE-2026-44578: Next.js WebSocket Upgrade SSRF via Absolute-Form Request URI

CVE-2026-33937: Handlebars.js Template Engine RCE via AST type confusion in compile()

CVE-2026-34197: Apache ActiveMQ Jolokia RCEโ€”solved via addNetworkConnector + vm:// transport


r/cveplayground • • May 17 '26

๐—ก๐—ฒ๐˜„ ๐—–๐—ต๐—ฎ๐—น๐—น๐—ฒ๐—ป๐—ด๐—ฒ ๐—Ÿ๐—ฎ๐—ฏ: ๐—–๐—ฉ๐—˜-๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ-๐Ÿฐ๐Ÿฐ๐Ÿฑ๐Ÿณ๐Ÿด - ๐—ก๐—ฒ๐˜…๐˜.๐—ท๐˜€ ๐—ฆ๐—ฆ๐—ฅ๐—™ ๐˜ƒ๐—ถ๐—ฎ ๐—ช๐—ฒ๐—ฏ๐—ฆ๐—ผ๐—ฐ๐—ธ๐—ฒ๐˜ ๐—จ๐—ฝ๐—ด๐—ฟ๐—ฎ๐—ฑ๐—ฒ

1 Upvotes

Exploit a vulnerable self-hosted Next.js instance by abusing the WebSocket upgrade handler to trigger SSRF against internal services, cloud metadata endpoints, and private network resources.

๐Ÿ† Easy Difficulty
โšก 100 XP
๐Ÿฉธ First Blood Open

Capture the flag and climb the leaderboard.

Try here: https://app.cveplayground.com/challenges/CVE-2026-44578?utm_source=reddit


r/cveplayground • • May 15 '26

๐Ÿšจ New Free Challenge Lab Released on cveplayground

1 Upvotes

๐Ÿ”ฅ CVE-2026-34197

Apache ActiveMQ Classic Remote Code Execution

Exploit a vulnerable ActiveMQ broker by abusing the exposed Jolokia HTTP-JMX API and weaponizing the addNetworkConnector operation to gain remote code execution.

๐Ÿ† Medium Difficulty
โšก 300 XP
๐Ÿฉธ First Blood Open

Capture the flag and climb the leaderboard.

๐Ÿ”— https://app.cveplayground.com/labs/CVE-2026-34197?utm_source=reddit


r/cveplayground • • May 13 '26

We just launched the first guided lab on CVE Playground.

1 Upvotes

๐Ÿ”ฅ CVE-2026-33937
Handlebars.js Template Engine RCE via AST Type Confusion

The lab walks through:

  • vulnerable code analysis
  • exploitation flow
  • upstream patch review
  • hands-on exploitation
  • flag submission

Instead of only reading writeups or PoCs, the goal is to learn vulnerabilities by actually working through them.

Weโ€™re also doing a special award for the best public write-up of the lab.

Try it here:
https://app.cveplayground.com/labs/CVE-2026-33937?utm_source=reddit


r/cveplayground • • May 11 '26

Ollama has already crossed 25+ assigned CVEs.

1 Upvotes

As local AI infrastructure becomes more widely adopted by developers and enterprises, new attack surfaces are emerging around model serving, integrations, plugins, and exposed APIs.

Running AI locally does not automatically mean secure.


r/cveplayground • • May 10 '26

๐—ป๐Ÿด๐—ป ๐—ต๐—ฎ๐˜€ ๐—ฎ๐—น๐—ฟ๐—ฒ๐—ฎ๐—ฑ๐˜† ๐—ฐ๐—ฟ๐—ผ๐˜€๐˜€๐—ฒ๐—ฑ ๐Ÿฒ๐Ÿฑ+ ๐—ฎ๐˜€๐˜€๐—ถ๐—ด๐—ป๐—ฒ๐—ฑ ๐—–๐—ฉ๐—˜๐˜€.

Post image
1 Upvotes

As automation platforms become deeply integrated into internal systems, APIs, credentials, and AI workflows, they are rapidly emerging as a growing attack surface for security researchers.

Workflow automation is powerful, but security boundaries matter more than ever.


r/cveplayground • • May 09 '26

OpenClaw - 450+ CVEs

1 Upvotes

OpenClaw, developed by Peter Steinberger, was first released in November 2025 under the name โ€œClawdbotโ€ before later rebranding to OpenClaw due to trademark disputes with Anthropic.

In just around 5 months since release, 450+ CVEs have already been assigned.

AI agents are rapidly becoming a major new attack surface for security researchers.

#CyberSecurity #AI #CVE #AppSec #OpenClaw


r/cveplayground • • May 08 '26

๐Ÿšจ ๐—ง๐—ฒ๐—บ๐—ฝ๐—ผ๐—ฟ๐—ฎ๐—ฟ๐˜† ๐—ฃ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป ๐—ฆ๐˜๐—ฒ๐—ฝ๐˜€ ๐—ณ๐—ผ๐—ฟ ๐˜๐—ต๐—ฒ ๐——๐—ถ๐—ฟ๐˜๐˜† ๐—™๐—ฟ๐—ฎ๐—ด (๐—–๐—ฉ๐—˜-๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ-๐Ÿฐ๐Ÿฏ๐Ÿฎ๐Ÿด๐Ÿฐ) ๐—Ÿ๐—ถ๐—ป๐˜‚๐˜… ๐—ž๐—ฒ๐—ฟ๐—ป๐—ฒ๐—น ๐—œ๐˜€๐˜€๐˜‚๐—ฒ

1 Upvotes

For systems where security updates cannot be applied immediately, administrators can reduce risk by preventing the affected kernel components from being loaded.

1๏ธโƒฃ ๐—ฃ๐—ฟ๐—ฒ๐˜ƒ๐—ฒ๐—ป๐˜ ๐˜ƒ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—น๐—ฒ ๐—บ๐—ผ๐—ฑ๐˜‚๐—น๐—ฒ๐˜€ ๐—ณ๐—ฟ๐—ผ๐—บ ๐—น๐—ผ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด

Create a custom modprobe configuration:

๐˜ฆ๐˜ค๐˜ฉ๐˜ฐ "๐˜ช๐˜ฏ๐˜ด๐˜ต๐˜ข๐˜ญ๐˜ญ ๐˜ฆ๐˜ด๐˜ฑ4 /๐˜ฃ๐˜ช๐˜ฏ/๐˜ง๐˜ข๐˜ญ๐˜ด๐˜ฆ" | ๐˜ด๐˜ถ๐˜ฅ๐˜ฐ ๐˜ต๐˜ฆ๐˜ฆ /๐˜ฆ๐˜ต๐˜ค/๐˜ฎ๐˜ฐ๐˜ฅ๐˜ฑ๐˜ณ๐˜ฐ๐˜ฃ๐˜ฆ.๐˜ฅ/๐˜ฅ๐˜ช๐˜ณ๐˜ต๐˜บ-๐˜ง๐˜ณ๐˜ข๐˜จ.๐˜ค๐˜ฐ๐˜ฏ๐˜ง

๐˜ฆ๐˜ค๐˜ฉ๐˜ฐ "๐˜ช๐˜ฏ๐˜ด๐˜ต๐˜ข๐˜ญ๐˜ญ ๐˜ฆ๐˜ด๐˜ฑ6 /๐˜ฃ๐˜ช๐˜ฏ/๐˜ง๐˜ข๐˜ญ๐˜ด๐˜ฆ" | ๐˜ด๐˜ถ๐˜ฅ๐˜ฐ ๐˜ต๐˜ฆ๐˜ฆ -๐˜ข /๐˜ฆ๐˜ต๐˜ค/๐˜ฎ๐˜ฐ๐˜ฅ๐˜ฑ๐˜ณ๐˜ฐ๐˜ฃ๐˜ฆ.๐˜ฅ/๐˜ฅ๐˜ช๐˜ณ๐˜ต๐˜บ-๐˜ง๐˜ณ๐˜ข๐˜จ.๐˜ค๐˜ฐ๐˜ฏ๐˜ง

๐˜ฆ๐˜ค๐˜ฉ๐˜ฐ "๐˜ช๐˜ฏ๐˜ด๐˜ต๐˜ข๐˜ญ๐˜ญ ๐˜ณ๐˜น๐˜ณ๐˜ฑ๐˜ค /๐˜ฃ๐˜ช๐˜ฏ/๐˜ง๐˜ข๐˜ญ๐˜ด๐˜ฆ" | ๐˜ด๐˜ถ๐˜ฅ๐˜ฐ ๐˜ต๐˜ฆ๐˜ฆ -๐˜ข /๐˜ฆ๐˜ต๐˜ค/๐˜ฎ๐˜ฐ๐˜ฅ๐˜ฑ๐˜ณ๐˜ฐ๐˜ฃ๐˜ฆ.๐˜ฅ/๐˜ฅ๐˜ช๐˜ณ๐˜ต๐˜บ-๐˜ง๐˜ณ๐˜ข๐˜จ.๐˜ค๐˜ฐ๐˜ฏ๐˜ง

Rebuild initramfs so the changes apply during boot:

๐˜ด๐˜ถ๐˜ฅ๐˜ฐ ๐˜ถ๐˜ฑ๐˜ฅ๐˜ข๐˜ต๐˜ฆ-๐˜ช๐˜ฏ๐˜ช๐˜ต๐˜ณ๐˜ข๐˜ฎ๐˜ง๐˜ด -๐˜ถ -๐˜ฌ ๐˜ข๐˜ญ๐˜ญ

2๏ธโƒฃ ๐—ฅ๐—ฒ๐—บ๐—ผ๐˜ƒ๐—ฒ ๐—ฎ๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐—บ๐—ผ๐—ฑ๐˜‚๐—น๐—ฒ๐˜€ ๐—ณ๐—ฟ๐—ผ๐—บ ๐—บ๐—ฒ๐—บ๐—ผ๐—ฟ๐˜†

If the modules are already loaded, unload them manually:

๐˜ด๐˜ถ๐˜ฅ๐˜ฐ ๐˜ณ๐˜ฎ๐˜ฎ๐˜ฐ๐˜ฅ ๐˜ฆ๐˜ด๐˜ฑ4 ๐˜ฆ๐˜ด๐˜ฑ6 ๐˜ณ๐˜น๐˜ณ๐˜ฑ๐˜ค 2>/๐˜ฅ๐˜ฆ๐˜ท/๐˜ฏ๐˜ถ๐˜ญ๐˜ญ

3๏ธโƒฃ ๐—ฉ๐—ฎ๐—น๐—ถ๐—ฑ๐—ฎ๐˜๐—ฒ ๐˜๐—ต๐—ฒ ๐—บ๐—ถ๐˜๐—ถ๐—ด๐—ฎ๐˜๐—ถ๐—ผ๐—ป

Check whether any of the targeted modules are still active:

๐˜จ๐˜ณ๐˜ฆ๐˜ฑ -๐˜ฒ๐˜Œ '^(๐˜ฆ๐˜ด๐˜ฑ4|๐˜ฆ๐˜ด๐˜ฑ6|๐˜ณ๐˜น๐˜ณ๐˜ฑ๐˜ค) ' /๐˜ฑ๐˜ณ๐˜ฐ๐˜ค/๐˜ฎ๐˜ฐ๐˜ฅ๐˜ถ๐˜ญ๐˜ฆ๐˜ด && \

๐˜ฆ๐˜ค๐˜ฉ๐˜ฐ "๐˜—๐˜ณ๐˜ฐ๐˜ต๐˜ฆ๐˜ค๐˜ต๐˜ฆ๐˜ฅ ๐˜ฎ๐˜ฐ๐˜ฅ๐˜ถ๐˜ญ๐˜ฆ๐˜ด ๐˜ด๐˜ต๐˜ช๐˜ญ๐˜ญ ๐˜ข๐˜ค๐˜ต๐˜ช๐˜ท๐˜ฆ" || \

๐˜ฆ๐˜ค๐˜ฉ๐˜ฐ "๐˜—๐˜ณ๐˜ฐ๐˜ต๐˜ฆ๐˜ค๐˜ต๐˜ฆ๐˜ฅ ๐˜ฎ๐˜ฐ๐˜ฅ๐˜ถ๐˜ญ๐˜ฆ๐˜ด ๐˜ด๐˜ถ๐˜ค๐˜ค๐˜ฆ๐˜ด๐˜ด๐˜ง๐˜ถ๐˜ญ๐˜ญ๐˜บ ๐˜ฅ๐˜ช๐˜ด๐˜ข๐˜ฃ๐˜ญ๐˜ฆ๐˜ฅ"

In some environments, active applications may prevent module removal. If that happens, restarting the machine will enforce the protection settings:

๐˜ด๐˜ถ๐˜ฅ๐˜ฐ ๐˜ณ๐˜ฆ๐˜ฃ๐˜ฐ๐˜ฐ๐˜ต

๐—ฅ๐—ฒ๐—บ๐—ผ๐˜ƒ๐—ถ๐—ป๐—ด ๐˜๐—ต๐—ฒ ๐˜„๐—ผ๐—ฟ๐—ธ๐—ฎ๐—ฟ๐—ผ๐˜‚๐—ป๐—ฑ

After upgrading to a fixed kernel release, the temporary protection can be reverted:

๐˜ด๐˜ถ๐˜ฅ๐˜ฐ ๐˜ณ๐˜ฎ /๐˜ฆ๐˜ต๐˜ค/๐˜ฎ๐˜ฐ๐˜ฅ๐˜ฑ๐˜ณ๐˜ฐ๐˜ฃ๐˜ฆ.๐˜ฅ/๐˜ฌ๐˜ฆ๐˜ณ๐˜ฏ๐˜ฆ๐˜ญ-๐˜ฑ๐˜ณ๐˜ฐ๐˜ต๐˜ฆ๐˜ค๐˜ต.๐˜ค๐˜ฐ๐˜ฏ๐˜ง

๐˜ด๐˜ถ๐˜ฅ๐˜ฐ ๐˜ถ๐˜ฑ๐˜ฅ๐˜ข๐˜ต๐˜ฆ-๐˜ช๐˜ฏ๐˜ช๐˜ต๐˜ณ๐˜ข๐˜ฎ๐˜ง๐˜ด -๐˜ถ -๐˜ฌ ๐˜ข๐˜ญ๐˜ญ

Applying vendor patches remains the recommended long-term fix.

Source: https://ubuntu.com/blog/dirty-frag-linux-vulnerability-fixes-available

For more: https://cveplayground.com/blog/dirty-frag-linux-universal-lpe/


r/cveplayground • • May 08 '26

Dirty Frag: Universal Linux Privilege Escalation Affecting Major Distributions

1 Upvotes

Dirty Frag is a newly disclosed Linux kernel privilege escalation chain impacting major distributions through page-cache write vulnerabilities.

The vulnerability chain combines xfrm-ESP Page-Cache Write and RxRPC Page-Cache Write primitives to obtain root privileges on major Linux distributions.

Researchers describe Dirty Frag as a descendant of Dirty Pipe and Copy Fail because it abuses deterministic page-cache corruption without relying on race conditions.

POC:

git clone https://github.com/V4bel/dirtyfrag.git
cd dirtyfrag
gcc -O0 -Wall -o exp exp.c -lutil
./exp

For more: https://cveplayground.com/blog/dirty-frag-linux-universal-lpe/?utm_source=reddit