
CVE-2026-72585-PoC
PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)

PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)

Zero-trust SSH bastion proxy with Vault-backed key management, RBAC policy enforcement, full session recording, and admin TUI for auditable access to…

SecureCivic is a citizen-built, open source identity verification platform designed for SSA adoption. It replaces private data brokers with a secure,…

Temporary WordPress plugin requiring authentication for the Core REST Batch API endpoint to mitigate the wp2shell vulnerability chain…

Privacy-first password manager with local storage and bring-your-own-cloud sync across Google Drive, Microsoft OneDrive, and Dropbox. Your…

Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.

OAuth 2.0 client library for Kit applications supporting authorization code, PKCE, client credentials, and refresh token flows with built-in provider…

A flexible, composable authorization framework for Kit (inspired by Action Policy)

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

gRPC-Go RBAC Authorization Policy Bypass via Missing `:path` Slash (Auth Bypass)

Research and analysis of the ServiceNow Virtual Agent vulnerability (CVE-2025-12420), including attack flow, MITRE ATT&CK mapping, detection…

Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI

A security-patched fork of the legacy ClickFunnels Classic WordPress plugin. Fixes critical Stored XSS vulnerabilities (CVE-2022-4782) while…

CVE-2026-23552 - Cross-Realm Token Acceptance in camel-keycloak

A security-hardened fork of Crowdsignal Forms. Patches CVE-2025-69015 (Broken Access Control), modernizes for PHP 8.2+, and enforces strict…

The Secure CommsOS™ for mission-critical operations

Open Source Identity and Access Management For Modern Applications and Services

Authorization library enforcing ACL, RBAC, ABAC, and custom access-control models with RESTful matching and policy management APIs for applications…