#1Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.
Kitploit recommended

Security-hardened fork of OpenCode - Fixes CVE-2026-22812 (CVSS 8.8 RCE) that upstream refuses to patch
Educational demo of three Claude Code vulnerabilities (hooks bypass, MCP injection, API key exfiltration) with attacker server, MITM proxy, and…

Exploit for CVE-2026-33017, an unauthenticated RCE in Langflow 1.8.1 via the build_public_tmp endpoint, enabling Python code injection through…

Technical analysis and Proof-of-Concept (PoC) for a critical Path Traversal vulnerability via Symlink manipulation in the Node.js 'tar' package…

Proof of concept and technical write-up for CVE-2026-31802, a symlink path traversal in npm tar allowing arbitrary file overwrite outside extraction…

Proof-of-concept demonstrating a hardlink path traversal in the tar npm package, allowing overwrite of files outside the extraction directory via…

Educational Python target range simulating CVE-2026-22807, an AI supply chain RCE via TOCTOU in model loading. Includes vulnerable library, PoC…

Proof-of-concept exploit for CVE-2026-21436, demonstrating path traversal in Solus OS eopkg package manager allowing arbitrary file write during…

Demonstrates AI agent-driven CVE remediation with cryptographic provenance tracking, showcasing detection, analysis, human approval, and verification…

Scanner de IOCs del ataque de cadena de suministro TeamPCP (CVE-2026-33634).

Minimal repro for Next.js 16.2.4 bundling picomatch 4.0.3 (CVE-2026-33671)

CVE-2026-31900 Vulnerable Lab - psf/black GitHub Action RCE

Companion source for YouTube video "Stop Mounting docker.sock — Run Trivy Without Giving Away Root Access — (inspired by CVE-2026-33634)"

Scan and patch tool for CVE-2021-44228 and related log4j concerns.

A Python pickling decompiler and static analyzer

AI-ready knowledge base of security & compliance regulations for hardware and connected-device manufacturers - structured, indexed, and…

Advisory and proof-of-concept for OS command injection in an MCP ffmpeg helper, with root-cause analysis, detector guidance, and mitigations for an…

Protection against Model Serialization Attacks