
vibe-coding-security
Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…


A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

List of regex for scraping secret API keys and juicy information.

Demonstrates CVE-2026-18953 arbitrary file write in an MCP server's get_resource tool by abusing savePath path traversal; includes vendored…

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Checklist of the most important security countermeasures when designing, testing, and releasing your API

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

Reproducer that exploits credential vending before location validation in Apache Polaris Iceberg REST, proving cross-tenant cloud reads and bucket…

Nuclei Templates Collection



FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

Damn Vulnerable MCP Server

A coverage-guided REST API fuzzer developed on top of LibAFL

Proof-of-concept exploit for CVE-2026-21003 demonstrating JWT authentication bypass by omitting the kid header and using the 'none' algorithm to…

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…