
PoC-CVE-2024-33883
PoC of CVE-2024-33883, RCE vulnerability of ejs.

PoC of CVE-2024-33883, RCE vulnerability of ejs.

Proof-of-concept exploit for CVE-2025-53964: remote file read/write via malicious XDXF dictionary in GoldenDict 1.5.0/1.5.1, leveraging unsanitized…

Detailed analysis of CVE-2024-28397, a sandbox escape vulnerability in js2py enabling RCE via Python object traversal. Includes code analysis, PoC,…

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

Generate malicious files using recently published homoglyphic-attack (CVE-2021-42694)

Test repository demonstrating a proof-of-concept for CVE-2021-23410 in msgpack, analyzing whether the reported deserialization vulnerability is…

React2Shell CVE-2025-55182: unauthenticated unsafe deserialization in React Server Components leading to reliable remote code execution via the…

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

Burp Suite JS Beautifier

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.