The catalog
Browse GHSA Reproductions
85 verified reproductions
Popular records
Top viewed reproduction records
Frequently opened evidence pages with direct links to runnable proof and permanent REPRO IDs.
REPRO-2026-00356 WordPress Core unauthenticated path traversal in get_page_template() page-template resolution leading to conditional RCE REPRO-2026-00354 GitLab CE/EE unauthenticated path traversal in Repository Commits API leads to arbitrary file read REPRO-2026-00341 JFrog Artifactory critical unauthenticated authentication bypass leading to administrative takeover REPRO-2026-00357 Next.js next/og ImageResponse RCE via Satori improper SVG escaping (critical) REPRO-2026-00337 Keycloak reset-credentials flow: unauthenticated account takeover (CWE-640) REPRO-2026-00355 ArangoDB full-chain: unauthenticated %5f URL auth bypass (GHSA-rrgq-978q-36mq) + client-controlled isSystem task escalation (GHSA-rvhw-4hpw-9vrx) -> root-context file write -> host RCE
85 reproductions
Clear filters Active GHSA
REPRO-2026-00054 published
Craft CMS: Unauthenticated Database Backup Trigger
CVE-2025-68456 critical Security composer
craftcms/cms
36m 45s Jan 8, 2026
REPRO-2026-00052 published
ComfyUI-Manager: Configuration File Exposure via Web-Accessible Path
CVE-2025-67303 high Security pip
ComfyUI-Manager
11m 32s Jan 8, 2026
REPRO-2026-00045 published
BentoML RCE via Insecure Deserialization
CVE-2025-27520 critical Security pip
bentoml
16m 37s Jan 7, 2026
REPRO-2026-00044 published
jsPDF Local File Inclusion/Path Traversal in Node.js builds
CVE-2025-68428 high Security npm
jspdf
8m 13s Jan 7, 2026
REPRO-2026-00001 published
Setuptools Path Traversal via PackageIndex.download
CVE-2025-47273 high Security pip
setuptools
14m 9s Jan 7, 2026