PoC for CVE-2026-46420, command injection in shivammathur/setup-php via repository-controlled PHP version resolution.
-
Updated
Jul 18, 2026
PoC for CVE-2026-46420, command injection in shivammathur/setup-php via repository-controlled PHP version resolution.
Advisory for git-js ⌯⌲ 11 mill weekly downloads
Reproducible research and local test environment for CNVD-2026-20654 (CWE-78)
Advisory for node-tesseract-ocr ⌯⌲ 50 000 weekly downloads
Advisory for textract ⌯⌲ 15 000 weekly downloads
Advisory for pdf-image ⌯⌲ 10 000 weekly downloads
POSIX shell in C with audit logging mapped to NIST SP 800-53, plus CWE-78 command injection and CWE-287 UID spoofing exploit demos with hardened fixes
Add a description, image, and links to the cwe-78 topic page so that developers can more easily learn about it.
To associate your repository with the cwe-78 topic, visit your repo's landing page and select "manage topics."