
auth-header-trust-rules
Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

Automate JWT Exploit (CVE-2018-0114)

A JWT based API for managing users and issuing JWT tokens

PHP-RBAC is an authorization library for PHP. It provides developers with NIST Level 2 Standard Role Based Access Control and more, in the fastest…

This repository discloses a server-side authorization bypass in Instagram, which allowed unauthenticated access to private timelines; it seems likely…

A terminal based tool for managing secrets with both tui and cli support

A modern git based age-encrypted secrets manager for teams.

Kernel-level security engine using eBPF-LSM to enforce file access policies based on process lineage, protecting sensitive data from supply-chain…

WireGuard-based zero-trust access platform providing secure, peer-to-peer remote access with granular policy controls, SSO authentication, and audit…

strongSwan - IPsec-based VPN

A tool to scan Kubernetes cluster for risky permissions

Open source Dropbox-like file sharing with full client encryption !


C exploit for CVE-2021-3560, an authentication bypass in polkit enabling unprivileged users to create a privileged account via DBus, with a detailed…

A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability…

A small, auditable, terminating, deterministic micro-policy engine

Terminal-based encrypted messenger with post-quantum cryptography, Double Ratchet protocol, and Tor anonymity. Features duress passphrase, deniable…

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…