#1Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.
Kitploit recommended

NPM Sec Analysis

Hello,

CVE-2018-6574 this vulnerability impacts Golang go get command and allows an attacker to gain code execution on a system by installing a malicious…

Educational lab simulating npm supply chain attacks, CI/CD abuse, and install-time code execution via CVE-2026-45321. Hands-on defensive security…

PoC: CVE-2025-30065 incomplete fix bypass in Apache Parquet Java 1.15.1

Detects known vulnerabilities in Ruby Gemfile dependencies by scanning for specific CVEs, enabling automated security checks in development pipelines.

Synthetic vulnerable Node.js HTTP server used as a demo target for the EXPOSURE vulnerability scanner, tracking CVE-2021-23797 with a one-click…

Script to obfuscate a payload the same way as it was done by the XZ utils attack (CVE-2024-3094)

Research environment and validation scripts for evaluating deserialization behaviors in MLflow and MLServer.

Demonstration of CVE-2025-62518: a critical PAX extended header size override bug in tokio-tar and async Rust tar libraries, with reproduction tools…

Hook for the PoC for exploiting CVE-2024-32002

deb/rpm repository for Trivy

History of commits related to the xz backdoor Discovered On March 29, 2024: CVE-2024-3094.

Security scanner to detect CVE-2025-55182 & CVE-2025-66478 vulnerabilities in React Server Components (RSC) projects

Proof-of-concept exploit for CVE-2024-32002, a Git submodule vulnerability enabling arbitrary code execution via crafted repositories and symlinks.

Minimal test repository demonstrating Git's CVE-2017-1000117 recursive clone vulnerability for educational exploitation verification.

Proof-of-concept demonstrating a path traversal vulnerability (CVE-2026-35204) in Helm plugin installation, allowing arbitrary file write via crafted…

Offline scanner for CVE-2026-29000 (CVSS 10.0) in org.pac4j:pac4j-jwt. Inspects jars/fat-jars directly, so it works where mvn dependency:tree cannot.…