
CVE-2024-3660-PoC
A PoC for CVE-2024-3660. Arbitrary Code Execution in Keras.

A PoC for CVE-2024-3660. Arbitrary Code Execution in Keras.

PoC for CVE-2025-62593: unauthenticated RCE in Ray (CISA KEV). Stdlib-only Python.

Expose and detail an unauthenticated stored XSS vulnerability in the Google Cloud Vertex AI Python SDK affecting versions 1.98.0 to 1.130.9.

vulnerability in CVE 2025-9998 and solution for those vulnerability with help artificial intelligence

Exploit for Langflow AI Remote Code Execution (Unauthenticated)

Artefacts for blog post on finding CVE-2025-37899 with o3

Proof-of-concept and analysis for CVE-2025-32711

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only

Research and analysis of the ServiceNow Virtual Agent vulnerability (CVE-2025-12420), including attack flow, MITRE ATT&CK mapping, detection…

AISec Plus Week 1 threat write-up — EchoLeak (CVE-2025-32711), zero-click indirect prompt injection in Microsoft 365 Copilot.

A tool that checks if a TorchServe instance is vulnerable to CVE-2023-43654



CVE-2025-31337 Security Advisory - Critical Buffer Overflow in AI Chatbot Framework

Ethical, network-isolated Docker lab reproducing CVE-2026-26030 — Semantic Kernel in-memory vector store filter eval() RCE (patched in 1.39.4)

CVE-2026-67598 — Emlog Pro: disabled TLS certificate validation in AI assistant (MITM → API-key theft). CWE-295, CVSS 9.1. Reported by @IlhomjonR.