RainLoop bug notes
authenticated command execution
The proof targets RainLoop 1.17.0 and requires a valid mailbox account. Its attachment workflow can be used to read the local data/SALT.php file. The PoC then forges a token that reaches an unsafe Predis deserialization chain and executes the supplied command as the web server account.
The bundle contains the PoC, its PHP token builder, and the RainLoop encryption helper it uses. Run it only against an installation you own or are authorized to test.
download proof bundle