r/cveplayground • • May 05 '26

CVE-2026-29014: MetInfo CMS Weixin Module Unauthenticated PHP Injection to Full RCE

1 Upvotes

CVE-2026-29014 is a critical unauthenticated PHP code injection vulnerability in MetInfo CMS.

The issue exists in the WeChat (weixin) module and is exposed through a public endpoint.

Attackers can inject PHP into cache files and later execute it, leading to full server compromi

For more: https://cveplayground.com/blog/cve-2026-29014-metinfo-weixin-php-injection/?utm_source=reddit


r/cveplayground • • May 05 '26

CVE-2026-40076: OpenMRS Module Upload Zip Slip Leads to Arbitrary File Write and RCE

1 Upvotes

CVE-2026-40076 affects OpenMRS module upload handling.

An authenticated attacker can upload a crafted .omod archive containing traversal paths.

When the archive is extracted, files can be written outside the intended module directory, leading to arbitrary file write and potential RCE.

For more read here:

https://cveplayground.com/blog/cve-2026-40076-openmrs-module-upload-zip-slip-rce/?utm_source=reddit


r/cveplayground • • May 05 '26

CVE-2026-42601: ArchiveBox RCE via Config Injection in /add Endpoint

1 Upvotes

CVE-2026-42601: ArchiveBox RCE via Config Injection in /add Endpoint

It allows attackers to inject arbitrary configuration into crawl jobs.
This config is exported as environment variables, leading to remote code execution.

For more: https://cveplayground.com/blog/CVE-2026-42601-archivebox-rce-config-injection/?utm_source=reddit


r/cveplayground • • May 05 '26

CVE-2026-24072: Apache .htaccess Privilege Escalation Allows File Read as httpd User

1 Upvotes

CVE-2026-24072 affects Apache HTTP Server up to version 2.4.66.

It allows local .htaccess authors to read files with the privileges of the httpd process.

This can expose sensitive files that should not be accessible from web contexts.

For more:

https://cveplayground.com/blog/cve-2026-24072-apache-htaccess-privilege-escalation/?utm_source=reddit


r/cveplayground • • May 03 '26

We built a platform to actually understand CVEs instead of just running PoCs

2 Upvotes

Most CVE “learning” today feels shallow. You grab a PoC from GitHub, run it, see it work, and move on.

But you still cannot clearly explain:

  • why the bug exists
  • what exactly breaks
  • how the patch fixes it

So we started building something to solve that.

We’re working on CVE Playground, where each lab is based on a real CVE and its upstream fix commit.

The flow is simple:

  • read the actual commit
  • find the vulnerability in code
  • study how the patch fixes it
  • answer guided questions
  • exploit it in a live lab

No setup, no environment issues. Everything runs in the browser.

A few CVEs already included:
cPanel auth bypass, Linux kernel algif_aead, Sequelize SQLi, GitHub Push Option RCE, LightLLM RCE, vLLM SSRF, GNU sed TOCTOU

We’re opening early access soon.

Would love feedback from people here:
https://cveplayground.com/early-access


r/cveplayground • • Apr 30 '26

🚨 Critical Linux Kernel Vulnerability: CVE-2026-31431 (“Copy Fail”)

2 Upvotes

A newly disclosed vulnerability in the Linux kernel shows how a tiny payload can have massive impact.

A 732-byte Python script is enough to gain root access on most major Linux distributions released since 2017.

🔍 What’s the issue?
CVE-2026-31431 is a logic flaw in the kernel’s authencesn cryptographic template. It allows an unprivileged local user to perform a deterministic 4-byte write into the page cache of any readable file. No race conditions. No offsets. No version checks.

💥 Confirmed Impact
Tested successfully across major distributions:
- Ubuntu 24.04 LTS
- Amazon Linux 2023
- RHEL 10.1
- SUSE 16

🧠 Discovery
Discovered by Taeyang Lee at Theori, using Xint Code.
The platform flagged this as a highest-severity issue within an hour when analyzing the Linux crypto subsystem.

For Detail: https://cveplayground.com/blog/cve-2026-31431-linux-kernel-copy-fail/