
toolbox
Collaborative application security testing between humans and agents via CLI and MCP

Collaborative application security testing between humans and agents via CLI and MCP

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Proof-of-concept exploit for CVE-2026-11103 demonstrating GraphQL rate-limit bypass through batching and field aliases; includes vulnerable Node.js…

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

A web-based vulnerability scanner for CVE-2025-55182, a critical Remote Code Execution (RCE) vulnerability in React Server Components.

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

Exploit for CVE-2021-30180 targeting Apache Dubbo RPC framework, enabling remote code execution via crafted RPC requests in vulnerable versions.

Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324

A PoC exploit for CVE-2021-4191 - GitLab User Enumeration.

Http request smuggling vulnerability scanner

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

An intentionally designed broken web application based on REST API.

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.