rfxn/cpanel-sessionscribe
Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery vulnerability disclosed 2026-04-28. Defense-in-depth active mitigation shim, ModSec rule pack, remote probe, on-host IOC scanner, and per-tier RE snapshot collector. GPL v2.
GitHub repository with 13 stars and 0 forks.
Language: Shell
Topics: cpanel, cve-2026-41940, incident-response, modsecurity, security-tools, vulnerability-detection, whm, sessionscribe, crlf-injection, forensics