# Remote Code Execution Vulnerabilities in Exploitarium: 7 Critical Exploits Analyzed

> Discover 7 critical remote code execution vulnerabilities in Exploitarium impacting Gogs Ladybird Discord Floci Firefox Nextcloud and Redis Explore diverse attack vectors

- Repository: [bikini/exploitarium](https://github.com/bikini/exploitarium)
- Tags: deep-dive
- Published: 2026-09-06

---

**Exploitarium contains seven documented remote code execution (RCE) vulnerabilities across Gogs, Ladybird, Discord, Floci, Firefox Nextcloud, and Redis—each demonstrating distinct attack vectors from CSRF bypass to memory corruption.**

The **bikini/exploitarium** repository is a curated collection of proof-of-concept exploits targeting real-world software. Each RCE case reveals how seemingly minor architectural flaws—missing CSRF tokens, dangling references, or unsafe template evaluation—can escalate into full server compromise. This analysis examines the technical mechanics of each vulnerability with executable reproduction steps.

## Gogs Admin CSRF → Git Hook RCE

The Gogs vulnerability demonstrates how **administrative functionality without CSRF protection** enables complete server takeover.

### Attack Flow

1. **CSRF the admin user-edit form**: The endpoint lacks a CSRF token, allowing an attacker to forge requests that enable `admin=on` and `allow_git_hook=on` for a normal account
2. **Write malicious Git hook**: The attacker uses the stock hook editor to create a `post-receive` hook containing arbitrary shell commands
3. **Trigger via Git push**: Any subsequent HTTP Git push executes the hook, running attacker-controlled commands on the server

### Reproduction

```bash
python poc.py \
  --target-base http://127.0.0.1:38081 \
  --admin-user siteadmin \
  --admin-password 'AdminPass123!' \
  --attacker-user attacker \
  --attacker-password 'AttackerPass123!' \
  --attacker-id 2 \
  --attacker-email attacker@example.test \
  --repo gogs-hook-proof \
  --marker-path /tmp/gogs_hook_proof.txt \
  --output proof.json

```

The marker file at [`/tmp/gogs_hook_proof.txt`](https://github.com/bikini/exploitarium/blob/main//tmp/gogs_hook_proof.txt) confirms remote command execution. Source: [[`gogs-admin-csrf-git-hook-rce-poc/poc.py`](https://github.com/bikini/exploitarium/blob/main/gogs-admin-csrf-git-hook-rce-poc/poc.py)](https://github.com/bikini/exploitarium/blob/main/gogs-admin-csrf-git-hook-rce-poc/poc.py)

---

## Ladybird WASM Host-Function RCE

This **use-after-free in WebAssembly host-function bindings** allows memory corruption leading to native code execution.

### Root Cause

The ESM host-function creation captures a `Wasm::FunctionType` **by reference**. After the caller returns, this dangling reference is used to determine result arity. Combined with a stale GC array reference, the attacker writes arbitrary native memory and ultimately invokes `system("/tmp/ladybird_wasm_esm_rce")`.

### Reproduction

```bash
rm -f /tmp/ladybird_wasm_esm_rce
Build/gui-sanitizers/bin/ladybird \
  --headless=screenshot \
  --screenshot-delay=20 \
  --screenshot-path=/tmp/ladybird-wasm-esm.png \
  file:///absolute/path/to/ladybird-wasm-esm-host-function-rce-poc/poc.html

ls -l /tmp/ladybird_wasm_esm_rce

```

The browser engine's memory corruption is triggered entirely through crafted WebAssembly. Source: [[`ladybird-wasm-esm-host-function-rce-poc/poc.html`](https://github.com/bikini/exploitarium/blob/main/ladybird-wasm-esm-host-function-rce-poc/poc.html)](https://github.com/bikini/exploitarium/blob/main/ladybird-wasm-esm-host-function-rce-poc/poc.html)

---

## Discord Activity → Native Windows Calculator RCE

A **renderer compromise in Discord's Electron-based client** achieves native process creation without any binary injection.

### Exploit Chain

- Obtain engine-memory primitive through crafted Activity page
- Patch auxiliary-window policy to bypass sandbox restrictions
- Use Electron IPC to invoke `CreateProcessW` with `calc.exe` path

The exploit runs entirely in the stock Discord client (version 1.0.9245).

### Reproduction

```powershell

# Establish HTTPS tunnel

cloudflared tunnel --url http://127.0.0.1:3077

# Launch PoC server with public origin

.\run.ps1 -PublicOrigin "https://your-tunnel-host.example.com"

```

Pressing **Run Calculator proof** in the Discord Activity launches Windows Calculator, confirming RCE from the Activity sandbox. Source: [[`discord-activity-stock-client-rce-poc/server.js`](https://github.com/bikini/exploitarium/blob/main/discord-activity-stock-client-rce-poc/server.js)](https://github.com/bikini/exploitarium/blob/main/discord-activity-stock-client-rce-poc/server.js)

---

## Floci API-Gateway VTL RCE

**Velocity Template Language (VTL) injection** in Floci 1.5.27 allows arbitrary Java execution through the API Gateway.

The VTL engine evaluates attacker-controlled templates without proper sandboxing. By chaining template injection with IAM scope bypass, the attacker executes Java payloads that write marker files on the server. Source: [[`floci-apigateway-vtl-rce-poc/README.md`](https://github.com/bikini/exploitarium/blob/main/floci-apigateway-vtl-rce-poc/README.md)](https://github.com/bikini/exploitarium/blob/main/floci-apigateway-vtl-rce-poc/README.md)

---

## Firefox 152.0.5 Backup NSS RCE

A **deserialization vulnerability in the NSS library backup import path** allows native payload execution through malicious archive processing.

The PoC generates a crafted backup archive that, when imported, triggers a native `calc` payload under the Firefox process. This demonstrates RCE via a malicious update file distributed through standard browser mechanisms. Source: [[`firefox-152.0.5-backup-nss-rce-poc/poc.py`](https://github.com/bikini/exploitarium/blob/main/firefox-152.0.5-backup-nss-rce-poc/poc.py)](https://github.com/bikini/exploitarium/blob/main/firefox-152.0.5-backup-nss-rce-poc/poc.py)

---

## Nextcloud Federated-Share Bearer-Token RCE

**Token scope confusion in Nextcloud 24+** enables command injection through the federated-share API.

A specially crafted bearer token granted to a remote server allows invocation of privileged API endpoints. Chaining path traversal with server-side command injection yields shell execution on the Nextcloud host. Source: [[`nextcloud-federated-share-bearer-token-poc/poc.py`](https://github.com/bikini/exploitarium/blob/main/nextcloud-federated-share-bearer-token-poc/poc.py)](https://github.com/bikini/exploitarium/blob/main/nextcloud-federated-share-bearer-token-poc/poc.py)

---

## Redis Vector-Set Duplicate HNSW ID RCE

**Use-after-free in the Vector-Set module's HNSW index** permits arbitrary code execution on the Redis server.

Crafted vector sets with duplicate HNSW IDs trigger memory corruption that allows function pointer overwrite. The attacker gains native code execution within the Redis process context. Source: [[`redis-vset-duplicate-hnsw-id-rce-poc/poc.py`](https://github.com/bikini/exploitarium/blob/main/redis-vset-duplicate-hnsw-id-rce-poc/poc.py)](https://github.com/bikini/exploitarium/blob/main/redis-vset-duplicate-hnsw-id-rce-poc/poc.py)

---

## Common Exploitation Patterns

Each remote code execution vulnerability in Exploitarium follows a predictable progression:

1. **Identify trusted entry point** — admin UI, ESM import, Activity renderer, template engine, backup importer, federated API, or native extension
2. **Manipulate state or memory** — CSRF, dangling reference, template injection, deserialization, token forgery, or heap corruption
3. **Escalate to native code** — Git hooks, `system()`, Windows API, Java `Runtime.exec()`, or function pointer overwrite

---

## Summary

- **Gogs RCE**: CSRF-protected admin functions missing tokens enable Git hook command injection
- **Ladybird RCE**: Dangling `Wasm::FunctionType` reference allows memory corruption through WASM
- **Discord RCE**: Electron IPC abuse from compromised renderer achieves native process creation
- **Floci RCE**: Unsandboxed VTL template evaluation permits arbitrary Java execution
- **Firefox RCE**: NSS backup deserialization bug triggers native payload via malicious archive
- **Nextcloud RCE**: Bearer token scope confusion leads to API command injection
- **Redis RCE**: Duplicate HNSW ID use-after-free enables function pointer overwrite

All PoCs include source traces, marker file verification, and reproducible steps in the bikini/exploitarium repository.

---

## Frequently Asked Questions

### How does the Gogs CSRF vulnerability bypass authentication?

The vulnerability does not bypass authentication—it exploits the **absence of CSRF tokens** on the admin user-edit form. An authenticated attacker tricks an admin into submitting a form that elevates a normal account to admin status and enables Git hook editing, which the attacker then uses for command execution.

### Can the Ladybird WASM exploit run without building from source?

No. The PoC requires a **sanitizer-instrumented build** of Ladybird (`gui-sanitizers/bin/ladybird`) to reliably trigger and detect the memory corruption. The exploit demonstrates the vulnerability class rather than attacking production builds.

### What makes the Discord Activity RCE significant for Electron security?

The exploit achieves **native code execution without any injected binaries or modified client**—purely through JavaScript execution in the Activity sandbox. This highlights risks in Electron's IPC design when renderer processes are compromised, particularly regarding auxiliary window policies and native API exposure.