#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

Practical security research project exploiting CVE-2025-32463 to gain root access on a vulnerable sudo version. Includes write-up, PoC, and…

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can…

This experiment is destinated to demonstrate how the DNS rebinding attack works on an emulated IoT. In the setup, we have a simulated IoT device,…

Next.js middleware auth-bypass lab (CVE-2025-29927 simulation)

ay 09 — CVE-2025-27520 (BentoML-style insecure deserialization) — Local Docker lab

This is a minimal, educational simulation that demonstrates the _impact_ class of a management-plane parsing RCE (inspired by CVE-2025-20265). It…

This tiny lab simulates the core idea behind CVE-2025-29306: unsafe use of `unserialize()` on attacker-controlled input leading to remote code…

Grafana SQL Expressions → DuckDB LFI (CVE-2024-9264)

Nexus Repository 3 Path Traversal (CVE-2024-4956)

This is a tiny lab that simulates the core idea reported for CVE-2025-54236 (“SessionReaper”)

CVE-2025-55182 React2Shell PoC lab

Sample docker-compose setup to show how this exploit works

Dockerized lab demonstrating CVE-2025-55182, a React Server Components vulnerability, with a proof-of-concept exploit for security research and…

Sets up a Dockerized environment to reproduce and analyze CVE-2024-47167, a vulnerability in Gradio 4.40.0, with an internal HTTP server and…

Exploiting CVE-2023-2825 on a VM

Proof-of-concept exploit demonstrating the Zip Slip vulnerability (CVE-2019-10743) in mholt/archiver, with a vulnerable server and Python payload for…

Next.js Middleware Bypass Vulnerability

Nuclei template and validation scripts for detecting CVE-2019-18935, a critical .NET deserialization RCE in Telerik UI for ASP.NET AJAX, with…