PoC files

1 file

File viewing is interactive and short-lived. Downloads are password-protected ZIP archives using password eip.

GitHub

Analysisdeepseek-v4-pro:cloud ·

Technical assessment

A README.md file providing a technical summary of CVE-2026-22241, an arbitrary file upload vulnerability in Open eClass. It describes the vulnerability, affected versions, root cause, and mitigation, but contains no exploit or scanner code.

Backdoor review

No backdoor observed in reviewed code

The supplied evidence consists solely of a README.md file that documents the CVE-2026-22241 vulnerability. It contains no executable code, no instructions to execute anything, and no concealed or deceptive payload. The content is a standard vulnerability disclosure with summary, affected versions, mitigation, and references.

ClassificationWriteup
Model confidence100%
AuthenticationRequired
LanguagesMarkdown
Target softwareOpen eClass
Attack typesUnrestricted File UploadRemote Code Execution
Evidence & reasoningClassification basis · observed behavior · safety review
Technical evidence

Classification basis and observed behavior

Classification basis

The artifact is a single README.md file that provides a substantive technical analysis of CVE-2026-22241, including a vulnerability summary, affected versions, root cause, and mitigation. It contains no executable code, exploit, or scanner logic, fitting the definition of a writeup.

0xBlackash-CVE-2026-22241-2df026c/README.md:1-82

Requirements

  • An authenticated administrator account is required to access the Theme Import feature.0xBlackash-CVE-2026-22241-2df026c/README.md:18

Observed behavior

  • The document describes the vulnerability, its impact (Remote Code Execution), and provides mitigation advice. It does not perform any actions.0xBlackash-CVE-2026-22241-2df026c/README.md:14-55
Safety-review evidence

Behaviors behind the backdoor verdict

Observables

File Content
README.mdThe only file in the evidence is a Markdown documentation file describing CVE-2026-22241. It contains no scripts, commands, or executable payloads.0xBlackash-CVE-2026-22241-2df026c/README.md:1-82
Review boundaries

What the analysis did not establish

  • The evidence consists of a single Markdown file; no source code, scripts, or binaries are present to confirm the presence of exploit or scanner functionality.
  • The analysis is based solely on the supplied text; the document's claims about the vulnerability are not independently verified.
  • Only the README.md file was provided; no other files from the repository directory were included in the evidence packet. The analysis scope confirms complete coverage of the selected text, but the artifact may contain additional files not reviewed here.
Model interpretation

This review is limited to the supplied PoC code and context. It does not assert that the code works or is safe to execute.

Linked vulnerabilities

1