# exploitarium | bikini | Knowledge Base | Instagit

A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.

GitHub Stars: 4.7k

Repository: https://github.com/bikini/exploitarium

---

## Articles

### [Where to Find the QEMU CXL Type-3 Mailbox Escape PoC: Complete Exploitarium Guide](/bikini/exploitarium/qemu-cxl-type-3-mailbox-escape-poc-location)

Find the QEMU CXL Type-3 Mailbox Escape PoC in the bikini/exploitarium GitHub repository. Get the complete exploitarium guide and explore the vulnerability.

- Tags: how-to-guide
- Published: 2026-09-07

### [Key Files for QEMU CXL Type-3 Mailbox Exploitation in Exploitarium](/bikini/exploitarium/exploitarium-qemu-cxl-key-files)

Explore the 7 key Exploitarium files crucial for QEMU CXL Type-3 mailbox exploitation. Understand the build and execution process for a successful guest-to-host escape.

- Tags: deep-dive
- Published: 2026-09-07

### [How to Trigger libc::system on QEMU Host from Guest: CXL Type-3 Mailbox Exploit](/bikini/exploitarium/trigger-libc-system-qemu-host-guest)

Learn how to trigger libc system on QEMU host from guest using a CXL Type-3 mailbox exploit. Execute arbitrary commands by leveraging an out-of-bounds read vulnerability. Proof of concept available.

- Tags: exploit-guide
- Published: 2026-09-07

### [How to Build the QEMU CXL PoC with build.sh](/bikini/exploitarium/build-qemu-cxl-poc-build-sh)

Easily build the QEMU CXL PoC with build.sh. Automate compilation of bootloader and payload, creating a bootable poc.img for QEMU.

- Tags: how-to-guide
- Published: 2026-09-07

### [What Is the Purpose of stage2.c in the QEMU CXL Exploit?](/bikini/exploitarium/purpose-stage2-c-qemu-cxl-exploit)

Discover the purpose of stage2.c in the QEMU CXL exploit. This code manipulates the CXL Type-3 mailbox interface to trigger host memory corruption and achieve arbitrary code execution.

- Tags: deep-dive
- Published: 2026-09-07

### [How to Use the QEMU CXL PoC Bootloader: Complete Setup and Execution Guide](/bikini/exploitarium/use-qemu-cxl-poc-bootloader)

Learn how to use the QEMU CXL PoC bootloader to demonstrate CXL mailbox escape vulnerabilities. This guide covers setup and execution for the two-stage bootloader.

- Tags: how-to-guide
- Published: 2026-09-07

### [How to Exploit the CXL SET_FEATURE Handler Vulnerability in QEMU: A Complete Guide](/bikini/exploitarium/exploit-qemu-cxl-set-feature-handler-vulnerability)

Learn to exploit the QEMU CXL SET_FEATURE handler vulnerability. Gain guest-to-host escape and execute arbitrary code with this comprehensive guide.

- Tags: how-to-guide
- Published: 2026-09-07

### [How to Exploit the CXL GET_LOG Handler Vulnerability in QEMU: A Full Chain Guide](/bikini/exploitarium/exploit-qemu-cxl-get-log-handler-vulnerability)

Exploit the CXL GET_LOG handler vulnerability in QEMU with this full chain guide. Learn to leak host pointers and achieve arbitrary code execution in the QEMU host process.

- Tags: how-to-guide
- Published: 2026-09-07

### [QEMU CXL Guest-to-Host Code Execution Vulnerability: Technical Analysis of the Type-3 Mailbox Escape](/bikini/exploitarium/qemu-cxl-guest-to-host-code-execution-vulnerability)

Uncover the QEMU CXL guest-to-host code execution vulnerability. Learn how two flaws in mailbox command handlers allow VM guests to run arbitrary commands on the host.

- Tags: technical-analysis
- Published: 2026-09-07

### [How to Escape QEMU CXL Type-3 Mailbox: A Full Exploit Walkthrough](/bikini/exploitarium/escape-qemu-cxl-type-3-mailbox)

Learn how to escape the QEMU CXL Type-3 mailbox by chaining an out-of-bounds read with an unbounded write to execute arbitrary host code. Full exploit walkthrough.

- Tags: exploit-walkthrough
- Published: 2026-09-07

### [Discord IPC Calls for RCE: Technical Analysis of the bikini/exploitarium Exploit](/bikini/exploitarium/discord-ipc-calls-rce)

Discover how Discord IPC calls enable RCE. Technical analysis of the bikini exploitarium exploit reveals attacker control via DISCORD_SETTINGS_SET and DISCORD_APP_RELAUNCH.

- Tags: deep-dive
- Published: 2026-09-07

### [How to Run the Discord RCE Exploit with run.ps1: A Complete Guide](/bikini/exploitarium/run-discord-rce-exploit-run-ps1)

Learn to run the Discord RCE exploit with run.ps1. Validate hashes, set your public origin, and let the PowerShell script manage the Node.js server and Discord settings restoration for you.

- Tags: how-to-guide
- Published: 2026-09-07

### [How to Use the Discord RCE PoC server.js: Complete Setup Guide](/bikini/exploitarium/use-discord-rce-poc-server-js)

Master the Discord RCE PoC server.js with our complete setup guide. Learn to manage exploit chains, generate payloads, and collect telemetry for effective exploitation.

- Tags: how-to-guide
- Published: 2026-09-07

### [How to Achieve RCE on Windows 11 via Discord Activity Iframe: Exploiting Discord 1.0.9245](/bikini/exploitarium/rce-windows-11-discord-activity-iframe)

Learn how to achieve RCE on Windows 11 via Discord Activity iframe by exploiting the V8 engine and Electron IPC bridge. Discover native code execution techniques.

- Tags: how-to-guide
- Published: 2026-09-07

### [V8 Type Confusion Vulnerability in Discord: Technical Analysis of the Electron Renderer Exploit](/bikini/exploitarium/v8-type-confusion-discord-vulnerability)

Understand the V8 type confusion vulnerability in Discord. Learn how JIT optimizations lead to sandbox escapes and native code execution via arbitrary read/write primitives.

- Tags: deep-dive
- Published: 2026-09-07

### [How Discord Electron IPC Exploits Work: Analyzing the Exploitarium Security Framework](/bikini/exploitarium/bypass-discord-sandbox-electron-ipc)

Learn how Discord Electron IPC exploits bypass the sandbox to execute code. Explore the bikini/exploitarium security framework for detailed analysis and techniques.

- Tags: deep-dive
- Published: 2026-09-07

### [Discord Activity to Native RCE Chain: 17-Step Exploit Breakdown](/bikini/exploitarium/discord-activity-native-rce-chain-steps)

Explore the 17-step Discord Activity to Native RCE exploit chain. Learn how to escalate from a sandboxed Activity page to arbitrary native code execution using V8 type confusion, popup policy manipulation, and Electron IPC hija...

- Tags: exploit-breakdown
- Published: 2026-09-07

### [How the Discord Activity RCE Exploit Works: From V8 Memory Corruption to Native Code Execution](/bikini/exploitarium/discord-activity-rce-exploit-how-it-works)

Uncover the Discord Activity RCE exploit, detailing V8 memory corruption and Electron IPC abuse for native code execution and launching Windows binaries.

- Tags: deep-dive
- Published: 2026-09-07

### [How to Use the Python Malicious SSH Server for libssh2 Exploit (CVE‑2026‑55200)](/bikini/exploitarium/use-python-malicious-ssh-server-libssh2-exploit)

Exploit CVE-2026-55200 using a Python malicious SSH server. Trigger integer overflow and out-of-bounds write in libssh2 clients with this detailed guide.

- Tags: how-to-guide
- Published: 2026-09-07

### [How to Build the libssh2 CVE-2026-55200 C11 Arithmetic Verifier](/bikini/exploitarium/build-libssh2-cve-2026-55200-c11-verifier)

Learn to build the libssh2 CVE-2026-55200 C11 arithmetic verifier. Compile and run the exploit to reproduce the 32-bit integer overflow vulnerability.

- Tags: how-to-guide
- Published: 2026-09-07

### [Fix for CVE-2026-55200 in libssh2: Integer Overflow Patch Explained](/bikini/exploitarium/fix-cve-2026-55200-libssh2)

Learn how the libssh2 fix for CVE-2026-55200 prevents integer overflow by rejecting malicious packet lengths early in transport.c. Understand the patch details now.

- Tags: deep-dive
- Published: 2026-09-07

### [How to Reproduce the libssh2 Transport Parser Integer Overflow (CVE‑2026‑55200)](/bikini/exploitarium/reproduce-libssh2-transport-parser-integer-overflow)

Reproduce the libssh2 transport parser integer overflow (CVE-2026-55200) by exploiting a 32-bit arithmetic wrap for out-of-bounds writes. Learn the technical details and exploit steps.

- Tags: how-to-guide
- Published: 2026-09-07

### [CVE-2026-55200: Integer Overflow Vulnerability in libssh2 Explained](/bikini/exploitarium/cve-2026-55200-libssh2-integer-overflow)

Understand CVE-2026-55200, a critical libssh2 integer overflow vulnerability. Learn how a crafted packet can lead to heap corruption and remote code execution on clients.

- Tags: deep-dive
- Published: 2026-09-07

### [How to Use Exploitarium for libssh2 CVE‑2026‑55200: A Step‑by‑Step Exploitation Guide](/bikini/exploitarium/exploitarium-libssh2-cve-2026-55200-usage)

Learn how to use Exploitarium for libssh2 CVE-2026-55200 exploitation. This guide details the PoC for local RCE via a malicious SSH handshake.

- Tags: how-to-guide
- Published: 2026-09-07

### [What Type of Bypass Is Exploited in flowise-mcp-env-case-bypass-poc?](/bikini/exploitarium/flowise-mcp-env-case-bypass-poc-bypass-type)

Discover the case variant environment variable bypass in Flowise's Custom MCP component. Learn how lowercase variants achieve RCE on Windows in this PoC exploit.

- Tags: deep-dive
- Published: 2026-09-06

### [Floci API Gateway VTL RCE Vulnerability: Attack Vector and Exploit Analysis](/bikini/exploitarium/floci-apigateway-vtl-rce-poc-vector)

Discover the attack vector for the Floci API Gateway VTL RCE vulnerability. Learn how unsandboxed Velocity template evaluation enables RCE and bypasses IAM credentials for control-plane access.

- Tags: exploit-analysis
- Published: 2026-09-06

### [How the Ladybird‑WASM‑ESM‑Host‑Function‑RCE‑PoC Achieves Remote Code Execution](/bikini/exploitarium/ladybird-wasm-esm-host-function-rce-poc-mechanism)

Discover how the ladybird-wasm-esm-host-function-rce-poc exploits JavaScript host functions, Wasm registers, and Memory64 leaks for remote code execution in Ladybird's WebContent process.

- Tags: deep-dive
- Published: 2026-09-06

### [Impact of the nghttp2-nghttpx-upgrade-queue-poison-poc Vulnerability: HTTP/1.1 Upgrade Queue Poisoning Explained](/bikini/exploitarium/nghttp2-nghttpx-upgrade-queue-poison-poc-impact)

Learn about the nghttp2-nghttpx-upgrade-queue-poison-poc vulnerability. Discover how attackers exploit HTTP/1.1 Upgrade headers for cross-client response injection and cache contamination.

- Tags: deep-dive
- Published: 2026-09-06

### [libssh2-publickey-list-calc-poc: Critical Vulnerabilities in the libssh2 Public Key Subsystem](/bikini/exploitarium/libssh2-publickey-list-calc-poc-issue)

Explore libssh2-publickey-list-calc-poc vulnerabilities. This proof-of-concept reveals arbitrary code execution flaws in the public-key subsystem, enabling attacker-controlled process spawning.

- Tags: deep-dive
- Published: 2026-09-06

### [What Is the Target of the anydesk-printer-com-impersonation-poc Vulnerability?](/bikini/exploitarium/anydesk-printer-com-impersonation-poc-target)

Understand the anydesk-printer-com-impersonation-poc vulnerability target. This exploit targets AnyDesk for Windows version 9.7.6 to escalate privileges to SYSTEM.

- Tags: deep-dive
- Published: 2026-09-06

### [What Component Does the 7zip-rar5-motw-chain-poc Vulnerability Affect?](/bikini/exploitarium/7zip-rar5-motw-chain-poc-component)

Discover how the 7zip-rar5-motw-chain-poc vulnerability affects the 7-Zip RAR5 extraction engine. Learn about its impact on ADS and MotW handling.

- Tags: deep-dive
- Published: 2026-09-06

### [How to Exploit the Discourse Scoped API Key Pre-Auth Bypass Vulnerability: A Technical Deep Dive](/bikini/exploitarium/discourse-scoped-api-key-preauth-bypass-exploitation)

Learn how to exploit the discourse-scoped-api-key-preauth-bypass vulnerability. Discover how to escalate read-only API keys to write access by bypassing HTTP verb validation. Get the technical details.

- Tags: deep-dive
- Published: 2026-09-06

### [Docker cp Copy-Out Destination Escape: Understanding the Container File Write Vulnerability](/bikini/exploitarium/docker-cp-copyout-destination-escape-type)

Explore the docker cp copy-out destination escape vulnerability. Learn how malicious containers write files outside designated host directories during docker cp operations.

- Tags: how-to-guide
- Published: 2026-09-06

### [Discord Activity Stock Client RCE PoC: Full Attack Chain Analysis](/bikini/exploitarium/discord-activity-stock-client-rce-poc-vector)

Analyze the discord-activity-stock-client-rce-poc vulnerability. Discover how V8 type confusion, memory patching, and Electron IPC abuse enable native code execution from a sandboxed Discord Activity.

- Tags: tutorial
- Published: 2026-09-06

### [firefox-152.0.5-backup-nss-rce-poc: Targeting Firefox’s NSS Module Loader for RCE](/bikini/exploitarium/firefox-152.0.5-backup-nss-rce-poc-target)

Discover the firefox-152.0.5-backup-nss-rce-poc exploit targeting Firefoxs NSS module loader. Learn how it achieves remote code execution via profile backup restoration.

- Tags: exploit-poc
- Published: 2026-09-06

### [How the curl SMTP EXPN Recipient CRLF Injection Vulnerability Works](/bikini/exploitarium/curl-smtp-expn-recipient-crlf-injection-mechanism)

Learn how the curl SMTP EXPN recipient CRLF injection vulnerability lets attackers insert commands by sending unsanitized recipient data to the server.

- Tags: deep-dive
- Published: 2026-09-06

### [Impact of the c-ares TCP Use-After-Free Vulnerability: A Deep Dive into the calc-poc RCE](/bikini/exploitarium/c-ares-tcp-uaf-calc-poc-impact)

Explore the c-ares TCP use-after-free vulnerability. Learn how calc-poc enables RCE by corrupting memory in ares_getaddrinfo and hijacking allocator hooks for arbitrary code execution.

- Tags: deep-dive
- Published: 2026-09-06

### [How to Find Local Privilege Escalation Exploits in the Exploitarium Repository](/bikini/exploitarium/exploitarium-local-privilege-escalation-exploits)

Discover local privilege escalation exploits in bikini's Exploitarium repository. Find PoC code for Windows LPE vulnerabilities and elevate your security testing.

- Tags: how-to-guide
- Published: 2026-09-06

### [Binary Parsing and Format Vulnerabilities in Exploitarium: 8 Critical PoCs Explained](/bikini/exploitarium/exploitarium-binary-parsing-format-vulnerabilities)

Discover 8 critical PoCs in Exploitarium targeting binary parsing and format vulnerabilities in ELF, ZIP, RIFF, VP9, and SSH. Learn about memory corruption and RCE.

- Tags: deep-dive
- Published: 2026-09-06

### [Authentication and Session Bypass Vulnerabilities in Exploitarium: Technical Analysis of 10 Critical PoCs](/bikini/exploitarium/exploitarium-authentication-session-bypass-vulnerabilities)

Explore 10 critical authentication and session bypass vulnerabilities in bikini/exploitarium. Discover technical analysis of flaws in remote desktop software, SSH agents, API gateways, and web platforms. Learn about exploit tec...

- Tags: deep-dive
- Published: 2026-09-06

### [Container and Virtualization Escape Vulnerabilities in the Exploitarium Repository](/bikini/exploitarium/exploitarium-container-virtualization-escapes)

Explore container and virtualization escape vulnerabilities in the bikini/exploitarium repo, including Docker cp race condition, Gitea act_runner bypass, and QEMU CXL exploit.

- Tags: deep-dive
- Published: 2026-09-06

### [Remote Code Execution Vulnerabilities in Exploitarium: 7 Critical Exploits Analyzed](/bikini/exploitarium/exploitarium-remote-code-execution-examples)

Discover 7 critical remote code execution vulnerabilities in Exploitarium impacting Gogs Ladybird Discord Floci Firefox Nextcloud and Redis Explore diverse attack vectors

- Tags: deep-dive
- Published: 2026-09-06

### [Browser Vulnerabilities with Proof-of-Concept Exploits in Exploitarium: Complete 2024 Catalog](/bikini/exploitarium/exploitarium-browser-web-technologies-exploits)

Explore browser vulnerabilities with proof-of-concept exploits in bikini/exploitarium. Discover exploits for Firefox, Ladybird, and Electron apps in our 2024 catalog.

- Tags: api-reference
- Published: 2026-09-06

### [Network and Protocol Vulnerabilities in Exploitarium: A Complete Taxonomy of PoC Exploits](/bikini/exploitarium/exploitarium-network-protocol-vulnerabilities)

Explore Exploitarium's comprehensive taxonomy of network and protocol vulnerabilities. Discover eight key families of exploits, including downgrade attacks, scope bypasses, and memory safety bugs.

- Tags: deep-dive
- Published: 2026-09-06

### [How Exploitarium Uses Git Operations to Ensure Bit-for-Bit Accuracy During Consolidation](/bikini/exploitarium/exploitarium-git-blob-id-matching-consolidation)

Learn how Exploitarium ensures bit-for-bit accuracy during consolidation by comparing Git tree data, blob SHA-1 hashes, and more, avoiding filesystem diffs for robust integrity.

- Tags: internals
- Published: 2026-09-06

### [How Exploitarium Verifies the Accuracy of Consolidated Repositories: Git Tree Verification Explained](/bikini/exploitarium/exploitarium-consolidation-verification-methodology)

Exploitarium employs Git tree verification to guarantee file accuracy in consolidated repositories. Learn how it ensures byte-for-byte matches with zero tolerance for divergence.

- Tags: how-to-guide
- Published: 2026-09-06

### [Direct Entries vs. Consolidated Repositories in Exploitarium: Key Differences Explained](/bikini/exploitarium/exploitarium-direct-vs-consolidated-repositories)

Understand the key differences between direct entries and consolidated repositories in Exploitarium. Learn how Exploitarium manages PoC folders and GitHub repo imports for efficient exploit management.

- Tags: deep-dive
- Published: 2026-09-06

### [How the Exploitarium Repository Is Structured for Each Vulnerability: A Complete Guide to Its PoC Architecture](/bikini/exploitarium/exploitarium-repository-structure-per-vulnerability)

Explore the Exploitarium repository structure for each vulnerability. Learn about its PoC architecture, featuring self-contained sub-directories, READMEs, and minimal PoC code for easy reproduction.

- Tags: architecture
- Published: 2026-09-06

