
vuln_apps
Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

Reproducer for CVE-2026-64640 — Apache Polaris Iceberg REST register/register-view vends storage credentials and reads an attacker-chosen metadata…

Enrolled agent can smuggle arbitrary OpenSearch _bulk operations via DataValue.index. GHSA-ff9g-85jq-r3g3. Draft


A secure persistent personal agent server in Rust. One binary, sandboxed execution, multi-provider LLMs, voice, memory, Telegram, WhatsApp, Discord,…

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

ArmourBird CSF - Container Security Framework

Browser privacy-leak detector — eight detection modules, risk scoring, and per-account history, all in your browser.

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

Fork of laravel/framework 10.50.2 with CVE-2026-48019 (CRLF injection in default email rule) backported into ValidatesAttributes::validateEmail.…

Proof-of-concept exploit for CVE-2022-4361, a reflected XSS vulnerability in Keycloak's OIDC authentication flow, with Docker-based test environment…

CVE-2026-23552 - Cross-Realm Token Acceptance in camel-keycloak

Proof-of-concept for CVE-2024-46627: unauthenticated REST API access control bypass in BECN DATAGERRY v2.2 allowing arbitrary user settings…

An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.